Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted

Project Subscriptions

Vendors Products
Systerel Subscribe
Advisories

No advisories yet.

Fixes

Solution

Use mbedtls cryptographic wrapper of S2OPC. Or upgrade S2OPC to use CycloneCrypto wrapper of release version >= 2.0.0 or master commit >= 839ae878


Workaround

No workaround given by the vendor.

History

Wed, 29 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Systerel
Systerel s2opc
Vendors & Products Systerel
Systerel s2opc

Wed, 29 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted
Title Improper Certificate Validation in S2OPC
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-29T18:04:53.132Z

Reserved: 2026-07-29T16:33:59.899Z

Link: CVE-2026-18257

cve-icon Vulnrichment

Updated: 2026-07-29T18:04:48.499Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T17:30:04Z

Weaknesses