CVE-2025-7390

CRITICAL

opc.https - Auth Bypass

Title source: llm
STIX 2.1

Description

A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.

Scores

CVSS v3 9.1
EPSS 0.0004
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-295
Status published
Products (9)
Softing/edgeAggregator < 2025.03
Softing/edgeAggregator SDEX Suite V1.0
Softing/edgeConnector < 2025.03
Softing/edgeConnector SDEX Suite V1.0
Softing/OPC UA C++ SDK 6.40 - 6.80
Softing/OPC UA C++ SDK 6.80.1
Softing Industrial Automation GmbH/edgeAggregator < 2025.03
Softing Industrial Automation GmbH/edgeConnector < 2025.03
Softing Industrial Automation GmbH/OPC UA C++ SDK 6.40 - 6.80
Published Aug 21, 2025
Tracked Since Feb 18, 2026