OPCFoundation.NetStandard.Opc.Ua.Core
OPC UA Core Class Library
Activity
- Latest release
- 3d ago
- Total releases
- 78
- Cadence
- ~16 days
- Last 12 months
- 12
Details
- License
- MIT
- First release
- Oct 09, 2020
| Version | Released | |
|---|---|---|
1.5.378.176
patch
| ||
2.0.0-preview.4
pre
|
2.0.0-preview.4
pre
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
2.0.0-preview.3
pre
|
2.0.0-preview.3
pre
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
2.0.0-preview.2
pre
|
2.0.0-preview.2
pre
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.5.378.156
patch
| ||
1.5.378.152
patch
| ||
1.5.378.145
patch
| ||
1.5.378.134
patch
| ||
1.5.378.106
patch
| ||
1.5.378.65
patch
| ||
1.5.378.10-preview
pre
| ||
1.5.377.22
patch
|
1.5.377.22
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.377.21
patch
|
1.5.377.21
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.377.11-preview
pre
|
1.5.377.11-preview
pre
Dependencies (5)
Changelog
Compare changes
|
|
1.5.376.244
patch
|
1.5.376.244
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.376.235
patch
|
1.5.376.235
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.376.213
patch
|
1.5.376.213
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.375.457
patch
|
1.5.375.457
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.176
patch
|
1.5.374.176
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.375.443
patch
|
1.5.375.443
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.168
patch
|
1.5.374.168
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.158
patch
|
1.5.374.158
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.126
patch
1 CVE
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev |
1.5.374.126
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.124
patch
1 CVE
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev |
1.5.374.124
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.118
patch
1 CVE
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev |
1.5.374.118
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.78
patch
2 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev |
1.5.374.78
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.375.71-ECC-preview
pre
|
1.5.375.71-ECC-preview
pre
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.70
patch
2 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev |
1.5.374.70
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.61-preview
pre
2 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev |
1.5.374.61-preview
pre
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.54
patch
2 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev |
1.5.374.54
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.50-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |
1.5.374.50-preview
pre
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.36
patch
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |
1.5.374.36
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.33-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |
1.5.374.33-preview
pre
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.27
patch
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |
1.5.374.27
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.374.26-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |
1.5.374.26-preview
pre
Dependencies (5)
Changelog
Compare changes
|
|
1.5.373.121
patch
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |
1.5.373.121
patch
Dependencies (5)
Changelog
Compare changes
|
|
1.5.373.3-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |
1.5.373.3-preview
pre
Dependencies (5)
Changelog
Compare changes
|
|
1.5.372.113
minor
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.107
patch
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.116-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.112-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.5.372.110-rc2
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.106
patch
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.91-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.76
patch
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.67-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.5.372.1-rc
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.56
patch
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.46-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
1.4.372.38-preview
pre
4 CVEs
CVE-2024-42512
GHSA-h958-fxgg-g7w3
Mar 03, 2025
Security Update for the OPC UA .NET Standard Stack
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. Note that the Basic128Rsa15 is disabled by default so most users will not be affected. When this patch is applied the Server closes all channels using the Basic128Rsa15 if an attack is detected. This introduces a DoS before any compromise can occur which is preferable to a compromise. To prevent this failure, applications must stop using Basic128Rsa15. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 71 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.118
1.5.374.124
1.5.374.126
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.158
References
Updated May 27, 2025 · Source: OSV.dev
CVE-2024-45526
GHSA-7vfh-cqpc-4267
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that allows an unauthorized attacker to trigger a gradual degradation in performance. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 68 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
1.5.374.54
1.5.374.61-preview
1.5.374.70
1.5.374.78
Fixed in
1.5.374.118
References Updated Oct 22, 2024 · Source: OSV.dev
GHSA-qm9f-c3v9-wphv
Oct 18, 2024
Security Update for the OPC UA .NET Standard Stack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
This security update resolves a vulnerability in the OPC UA .NET Standard Stack that enables an unauthorized attacker to trigger a rapid increase in memory consumption. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.05.374.54
References Updated Nov 28, 2024 · Source: OSV.dev
CVE-2024-33862
GHSA-4q2p-hwmr-qcxc
Jul 06, 2024
OPCFoundation.NetStandard.Opc.Ua.Core buffer-management vulnerability
High
Network
Low
None
None
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.5.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS) condition, disrupting the normal operation of the system. Affected versions
0.0.3
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
+ 64 more Show less
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.4.363.104-preview
1.4.363.107
1.4.364.40
1.4.365-gfc341ee8c5
1.4.365.1-preview
1.4.365.10
1.4.365.2
1.4.365.23
1.4.365.48
1.4.366.31-preview
1.4.366.38
1.4.367.100
1.4.367.39
1.4.367.41
1.4.367.42
1.4.367.64-preview
1.4.367.75
1.4.367.95
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.369.30
1.4.370.1
1.4.370.12
1.4.370.9
1.4.371.41
1.4.371.50
1.4.371.60
1.4.371.86
1.4.371.91
1.4.371.96
1.4.372.106
1.4.372.107
1.4.372.112-preview
1.4.372.116-preview
1.4.372.38-preview
1.4.372.46-preview
1.4.372.56
1.4.372.67-preview
1.4.372.76
1.4.372.91-preview
1.5.368.2-rc0
1.5.368.3-rc0
1.5.368.5-beta
1.5.371.3-beta
1.5.372.1-rc
1.5.372.110-rc2
1.5.372.113
1.5.373.121
1.5.373.3-preview
1.5.374.26-preview
1.5.374.27
1.5.374.33-preview
1.5.374.36
1.5.374.50-preview
Fixed in
1.5.374.54
References
Updated Jul 08, 2024 · Source: OSV.dev |