CVE-2018-12087

Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opcfoundation:ua-.net-legacy:*:*:*:*:*:*:*:*
cpe:2.3:a:opcfoundation:ua-.netstandard:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:44

Type Values Removed Values Added
References () https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2018-12087.pdf - Mitigation, Vendor Advisory () https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2018-12087.pdf - Mitigation, Vendor Advisory

Information

Published : 2018-10-03 18:29

Updated : 2024-11-21 03:44


NVD link : CVE-2018-12087

Mitre link : CVE-2018-12087

CVE.ORG link : CVE-2018-12087


JSON object : View

Products Affected

opcfoundation

  • ua-.net-legacy
  • ua-.netstandard
CWE
CWE-295

Improper Certificate Validation