Impact
An improper validity period check of the root issuer certificate in the CycloneCrypto cryptographic wrapper of S2OPC (CWE-295) allows a certificate issued by that root to be considered trusted. If an attacker can present a certificate that should have expired or otherwise should be rejected, the software will treat it as legitimate, enabling impersonation of a trusted entity and potential unauthorized access to protected resources.
Affected Systems
The vulnerability affects the Systerel S2OPC software. The issue is present in releases that use the CycloneCrypto cryptographic wrapper prior to version 2.0.0, or any commit earlier than 839ae878. Configurations that do not fallback to the mbedtls wrapper are also vulnerable.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity, and the EPSS < 1% shows a very low likelihood of exploitation at the time of this assessment. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would most likely require the attacker to supply a malicious certificate through a trusted channel or to compromise the certificate issuance process.
OpenCVE Enrichment