Description
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
Problem types
CWE-295 Improper Certificate Validation
Product status
6.40
Any version
Any version
References
industrial.softing.com/.../downloads/2025/CVE-2025-7390.html
industrial.softing.com/.../downloads/2025/CVE-2025-7390.json