Description
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
Scores
CVSS v3
9.1
EPSS
0.0004
EPSS Percentile
10.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-295
Status
published
Products (9)
Softing/edgeAggregator
< 2025.03
Softing/edgeAggregator
SDEX Suite V1.0
Softing/edgeConnector
< 2025.03
Softing/edgeConnector
SDEX Suite V1.0
Softing/OPC UA C++ SDK
6.40 - 6.80
Softing/OPC UA C++ SDK
6.80.1
Softing Industrial Automation GmbH/edgeAggregator
< 2025.03
Softing Industrial Automation GmbH/edgeConnector
< 2025.03
Softing Industrial Automation GmbH/OPC UA C++ SDK
6.40 - 6.80
Published
Aug 21, 2025
Tracked Since
Feb 18, 2026