Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.com/systerel/S2OPC/-/work_items/1739 |
|
History
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Systerel
Systerel s2opc |
|
| Vendors & Products |
Systerel
Systerel s2opc |
Tue, 09 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate. | |
| Title | Improper Check for Certificate Revocation in S2OPC | |
| Weaknesses | CWE-299 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-06-09T14:25:59.888Z
Reserved: 2026-04-23T07:01:03.918Z
Link: CVE-2026-6899
Updated: 2026-06-09T14:25:52.844Z
Status : Deferred
Published: 2026-06-09T09:16:30.737
Modified: 2026-06-09T15:25:56.860
Link: CVE-2026-6899
No data.
OpenCVE Enrichment
Updated: 2026-06-09T10:00:07Z