{"id":"CVE-2018-12087","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-12087","summary":"Moderate severity vulnerability that affects OPCFoundation.NetStandard.Opc.Ua","details":"Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.","published":"2018-10-16T19:51:18Z","modified":"2023-11-08T03:59:49.175653Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"NuGet","name":"OPCFoundation.NetStandard.Opc.Ua","fixedVersion":"1.4.353.15"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12087"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8336-mxp6-v5h9"},{"type":"WEB","url":"https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2018-12087.pdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:59:49.175653Z"}}