Certificate Revocation Issue in S2OPC Library Affecting CycloneCrypto
CVE-2026-6899

5.6MEDIUM

Key Information:

Vendor

Systerel

Status
Vendor
CVE Published:
9 June 2026

What is CVE-2026-6899?

The S2OPC library's CycloneCrypto component has a vulnerability that compromises certificate revocation checks. It only checks the first matching Certificate Revocation List (CRL), neglecting additional valid CRLs issued by the same Certificate Authority (CA). This flaw may enable an OPC UA client and server to establish a connection using certificates that have been revoked, potentially exposing systems to security risks.

Affected Version(s)

S2OPC 1.5.0 < 1.7.3

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Systerel
.