← Retour aux CVEs
CVE-2025-11043
HIGH7.4
Description
An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges.
Details CVE
Score CVSS v3.17.4
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie1/19/2026
Derniere modification1/26/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-295
References
https://www.br-automation.com/fileadmin/SA25P004-4f45197f.pdf(cybersecurity@ch.abb.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.