8.6
CVE-2024-42512
- EPSS 0.05%
- Veröffentlicht 10.02.2025 19:15:37
- Zuletzt bearbeitet 29.09.2025 18:13:38
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opcfoundation ≫ Ua .Net Standard Stack Version < 1.5.374.158
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.157 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.6 | 3.9 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
|
CWE-208 Observable Timing Discrepancy
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.