Lucene search

K
cveMitreCVE-2018-7559
HistoryJun 13, 2018 - 6:29 p.m.

CVE-2018-7559

2018-06-1318:29:00
CWE-320
mitre
web.nvd.nist.gov
57
opc ua
.net standard
stack
sample code
vulnerability
remote attacker
server's private key
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

54.1%

An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server’s private key by sending carefully constructed bad UserIdentityTokens as part of an oracle attack.

Affected configurations

Nvd
Node
opcfoundationua-.net-legacyRange1.03.342
OR
opcfoundationua-.netstandardRange1.03.352.10
VendorProductVersionCPE
opcfoundationua-.net-legacy*cpe:2.3:a:opcfoundation:ua-.net-legacy:*:*:*:*:*:*:*:*
opcfoundationua-.netstandard*cpe:2.3:a:opcfoundation:ua-.netstandard:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

54.1%

Related for CVE-2018-7559