CVE-2026-6899

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.

Scoring

Severity
MEDIUM
CVSS base score
5.6
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS probability
0.11%
CWE
CWE-299
Published
2026-06-09
Last modified
2026-06-09

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs