GHSA-xg6h-qgc7-qqr7MediumCVSS 6.5
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce...
🔗 CVE IDs covered (1)
📋 Description
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-63248
- https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc36069e2a
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598
- https://github.com/advisories/GHSA-xg6h-qgc7-qqr7