Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVSS Score
9.6
EPSS Score
0.002
Published
2026-08-04
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-08-04
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-08-04
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVSS Score
8.1
EPSS Score
0.002
Published
2026-08-04
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-08-04
Memory corruption while processing a packet with a size close to the maximum allowed value.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-08-04
Memory Corruption when processing registry values with incorrect types using a direct query method.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-08-04
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-08-04
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
CVSS Score
6.9
EPSS Score
0.002
Published
2026-08-04
In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.
CVSS Score
8.7
EPSS Score
0.004
Published
2026-08-04


Contact Us

Shodan ® - All rights reserved