Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.com/systerel/S2OPC/-/work_items/1739 |
|
History
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Systerel
Systerel s2opc |
|
| Vendors & Products |
Systerel
Systerel s2opc |
Tue, 09 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate. | |
| Title | Improper Check for Certificate Revocation in S2OPC | |
| Weaknesses | CWE-299 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published: 2026-06-09T08:39:00.495Z
Updated: 2026-06-09T08:39:00.495Z
Reserved: 2026-04-23T07:01:03.918Z
Link: CVE-2026-6899
No data.
Status : Received
Published: 2026-06-09T09:16:30.737
Modified: 2026-06-09T09:16:30.737
Link: CVE-2026-6899
No data.