8.6
CVE-2024-42512
- EPSS 0.08%
- Veröffentlicht 10.02.2025 19:15:37
- Zuletzt bearbeitet 29.09.2025 18:13:38
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opcfoundation ≫ Ua .Net Standard Stack Version < 1.5.374.158
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.248 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.6 | 3.9 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
|
CWE-208 Observable Timing Discrepancy
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.