Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Eclipse Milo 授权问题漏洞
Vulnerability Description
Eclipse Milo是美国Eclipse基金会开源的一个实现OPCUA协议的通信栈库。 Eclipse Milo 1.0.0版本至1.1.4版本存在授权问题漏洞,该漏洞源于OpcUaServerConfig.copy()未能保留配置的RoleMapper,可能导致会话未收到角色ID且默认访问控制器跳过角色权限检查,允许匿名客户端读取角色权限元数据、调用受保护方法或删除受保护节点。
CVSS Information
N/A
Vulnerability Type
N/A