CVE-2025-7390
CRITICALOPC UA C++ SDK 6.40-6.79 and >=6.80.1 - Improper Certificate Validation
Title source: llmDescription
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
References (2)
Core 2
Core References
Scores
CVSS v3
9.1
EPSS
0.0024
EPSS Percentile
14.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-295
Status
published
Products (9)
Softing/edgeAggregator
< 2025.03
Softing/edgeAggregator
SDEX Suite V1.0
Softing/edgeConnector
< 2025.03
Softing/edgeConnector
SDEX Suite V1.0
Softing/OPC UA C++ SDK
6.40 - 6.80
Softing/OPC UA C++ SDK
6.80.1
Softing Industrial Automation GmbH/edgeAggregator
< 2025.03
Softing Industrial Automation GmbH/edgeConnector
< 2025.03
Softing Industrial Automation GmbH/OPC UA C++ SDK
6.40 - 6.80
Published
Aug 21, 2025
Tracked Since
Feb 18, 2026