First published: Mon Mar 16 2020(Updated: )
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opcfoundation Netstandard.opc.ua | <1.4.359.31 | |
Opcfoundation Ua-.netstandard | =1.4.357.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19135 is a vulnerability in the OPC Foundation OPC UA .NET Standard codebase 1.4.357.28 servers.
CVE-2019-19135 has a severity of 7.4, which is considered high.
CVE-2019-19135 allows man-in-the-middle attackers to reuse encrypted user credentials sent over the network.
CVE-2019-19135 affects the OPC Foundation OPC UA .NET Standard codebase versions up to and excluding 1.4.359.31, as well as version 1.4.357.28 of UA-.NETStandard.
To fix CVE-2019-19135, it is recommended to update the OPC Foundation OPC UA .NET Standard codebase to version 1.4.359.31 or later.