CVE-2019-19135 describes a weakness in the OPC Foundation OPC UA .NET Standard codebase (versions prior to 1.4.359.31) where servers generate insufficiently random numbers, specifically impacting the OPCFoundation.NetStandard.Opc.Ua component. This vulnerability, rated 7.4 HIGH, allows remote man-in-the-middle attackers to reuse encrypted user credentials transmitted over the network due to the weak randomness. While the attack complexity is high, successful exploitation could lead to high confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.359.31CPE matchmatch criteria | cpe:2.3:a:opcfoundation:netstandard.opc.ua:*:*:*:*:*:*:*:* | ||
1.4.357.28CPE matchmatch criteria | cpe:2.3:a:opcfoundation:ua-.netstandard:1.4.357.28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.