GHSA-xg6h-qgc7-qqr7MediumCVSS 6.5

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce...

Published
August 4, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

🔗 References (5)