CVE 9.1 CRITICAL

Bypass the client certificate trust check of an opc.https server while only secure communication is allowed_CVE-2025-7390

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.

Basic Information

ID CVE-2025-7390
Source Softing
Published Aug 21, 2025 at 06:08

Affected Product

Vendor Softing Industrial Automation GmbH
Product OPC UA C++ SDK
Version 6.40
Affected Versions Softing Industrial Automation GmbH OPC UA C++ SDK 6.40
Softing Industrial Automation GmbH edgeConnector 0
Softing Industrial Automation GmbH edgeAggregator 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.