CVE-2024-42513: Medium severity opc foundation ua-.netstandard vulnerability
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-4rcc-7pg7-f57f. This link is maintained to preserve external references.
Original Description Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.
Other sources
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42513?
CVE-2024-42513 is classified as a high severity vulnerability due to the potential for unauthorized attackers to bypass authentication.
How do I fix CVE-2024-42513?
To fix CVE-2024-42513, update the OPC Foundation .NET Standard Stack to version 1.5.374.158 or later.
What is the impact of CVE-2024-42513?
The impact of CVE-2024-42513 allows unauthorized access to applications using HTTPS endpoints, compromising security.
Which software is affected by CVE-2024-42513?
CVE-2024-42513 affects the OPC Foundation .NET Standard Stack versions prior to 1.5.374.158.
How does CVE-2024-42513 exploit HTTPS endpoints?
CVE-2024-42513 exploits a flaw that allows attackers to bypass application authentication on HTTPS endpoints.