Description
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
Published: 2025-08-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

OPC UA C++ SDK V6.80.1 Service-Patch

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25419 A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
History

Fri, 27 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Softing opc Ua C Sdk
CPEs cpe:2.3:a:softing:edgeaggregator:*:*:linux:*:*:*:*:*
cpe:2.3:a:softing:edgeaggregator:sdex_suite_v1.0:*:linux:*:*:*:*:*
cpe:2.3:a:softing:edgeconnector:*:*:linux:*:*:*:*:*
cpe:2.3:a:softing:edgeconnector:sdex_suite_v1.0:*:linux:*:*:*:*:*
cpe:2.3:a:softing:opc_ua_c_sdk:*:*:linux:*:*:*:*:*
cpe:2.3:a:softing:opc_ua_c_sdk:*:*:vxworks:*:*:*:*:*
cpe:2.3:a:softing:opc_ua_c_sdk:*:*:windows:*:*:*:*:*
cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:linux:*:*:*:*:*
cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:vxworks:*:*:*:*:*
cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:windows:*:*:*:*:*
Vendors & Products Softing opc Ua C Sdk

Thu, 21 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Softing
Softing edgeaggregator
Softing edgeconnector
Softing opc
Vendors & Products Softing
Softing edgeaggregator
Softing edgeconnector
Softing opc

Thu, 21 Aug 2025 06:15:00 +0000

Type Values Removed Values Added
Description A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
Title Bypass the client certificate trust check of an opc.https server while only secure communication is allowed
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Softing Edgeaggregator Edgeconnector Opc Opc Ua C Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: Softing

Published:

Updated: 2026-03-27T08:36:30.497Z

Reserved: 2025-07-09T13:09:38.988Z

Link: CVE-2025-7390

cve-icon Vulnrichment

Updated: 2025-08-21T13:51:57.325Z

cve-icon NVD

Status : Deferred

Published: 2025-08-21T06:15:35.157

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-7390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-21T12:58:56Z

Weaknesses