-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| OPCFoundation.NetStandard.Opc.Ua | nuget | < 1.5.374.158 | 1.5.374.158 |
The vulnerability stems from the use of the deprecated Basic128Rsa15 security policy, which relies on RSA-PKCS1-v1.5. This padding scheme is known to have timing side-channels (CWE-208) and weak key validation (CWE-639). Functions responsible for selecting the security policy (e.g., GetSecurityPolicy) and performing RSA decryption (e.g., RsaUtils.Decrypt) are likely vulnerable. The confidence is medium because the exact code is unavailable, but the CWEs and vulnerability context strongly suggest these components.
Ongoing coverage of React2Shell