CVE-2026-6899
MEDIUM
5,6
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: low
Description
AI Translation Available
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0002
Percentile
0,1th
Updated
EPSS Score Trend (Last 6 Days)
299
Improper Check for Certificate Revocation
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Other
Confidentiality
Potential Impacts:
Gain Privileges Or Assume Identity
Other
Read Application Data
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based
https://gitlab.com/systerel/S2OPC/-/work_items/1739