No advisories yet.
Solution
Use MbedTLS cryptographic wrapper, or upgrade S2OPC to commit 3ff81301d95a77260e9deb791585a620c5623028 or release version > 1.7.2
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://gitlab.com/systerel/S2OPC/-/work_items/1739 |
|
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Systerel
Systerel s2opc |
|
| Vendors & Products |
Systerel
Systerel s2opc |
Tue, 09 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate. | |
| Title | Improper Check for Certificate Revocation in S2OPC | |
| Weaknesses | CWE-299 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-06-09T14:25:59.888Z
Reserved: 2026-04-23T07:01:03.918Z
Link: CVE-2026-6899
Updated: 2026-06-09T14:25:52.844Z
Status : Deferred
Published: 2026-06-09T09:16:30.737
Modified: 2026-06-09T15:25:56.860
Link: CVE-2026-6899
No data.
OpenCVE Enrichment
Updated: 2026-06-09T10:00:07Z