← Back to CVE search

CVE-2026-6899

S2OPC library

Description

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.

CVSS 5.6EPSS 0.108%Risk 0.57
View source
Published
2026-06-09 09:16:30
Affected versions
unknown
Type
Core software
Last modified
2026-07-23 08:10:00
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L