CVE-2019-19135: High severity opc foundation ua-.netstandard vulnerability
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-19135?
CVE-2019-19135 is a vulnerability in the OPC Foundation OPC UA .NET Standard codebase 1.4.357.28 servers.
What is the severity of CVE-2019-19135?
CVE-2019-19135 has a severity of 7.4, which is considered high.
How does CVE-2019-19135 affect the OPC UA .NET Standard servers?
CVE-2019-19135 allows man-in-the-middle attackers to reuse encrypted user credentials sent over the network.
Which software versions are affected by CVE-2019-19135?
CVE-2019-19135 affects the OPC Foundation OPC UA .NET Standard codebase versions up to and excluding 1.4.359.31, as well as version 1.4.357.28 of UA-.NETStandard.
How can I fix the CVE-2019-19135 vulnerability?
To fix CVE-2019-19135, it is recommended to update the OPC Foundation OPC UA .NET Standard codebase to version 1.4.359.31 or later.