{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-6899",
        "assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
        "state": "PUBLISHED",
        "assignerShortName": "GitLab",
        "dateReserved": "2026-04-23T07:01:03.918Z",
        "datePublished": "2026-06-09T08:39:00.495Z",
        "dateUpdated": "2026-06-09T14:25:59.888Z"
    },
    "containers": {
        "cna": {
            "title": "Improper Check for Certificate Revocation in S2OPC",
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate."
                }
            ],
            "affected": [
                {
                    "vendor": "Systerel",
                    "product": "S2OPC",
                    "versions": [
                        {
                            "version": "1.5.0",
                            "status": "affected",
                            "lessThan": "1.7.3",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "description": "CWE-299: Improper Check for Certificate Revocation",
                            "cweId": "CWE-299",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://gitlab.com/systerel/S2OPC/-/work_items/1739"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "attackVector": "NETWORK",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "LOW",
                        "integrityImpact": "LOW",
                        "availabilityImpact": "LOW",
                        "baseScore": 5.6,
                        "baseSeverity": "MEDIUM"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Use MbedTLS cryptographic wrapper, or upgrade S2OPC to commit 3ff81301d95a77260e9deb791585a620c5623028 or release version > 1.7.2"
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Systerel",
                    "type": "finder"
                }
            ],
            "providerMetadata": {
                "orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
                "shortName": "GitLab",
                "dateUpdated": "2026-06-09T08:39:00.495Z"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-06-09T14:25:36.868407Z",
                                "id": "CVE-2026-6899",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-06-09T14:25:59.888Z"
                }
            }
        ]
    }
}