Eclipse
Eclipse Milo: vulnerabilidades y CVE
Eclipse Milo tiene 8 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63252 | Alta (8.7) | 0.58% | — | 4 ago 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct… |
| CVE-2026-63248 | Media (6.9) | 0.26% | — | 4 ago 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a… |
| CVE-2026-62927 | Alta (8.7) | 0.42% | — | 4 ago 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to… |
| CVE-2026-61387 | Media (6.9) | 0.62% | — | 4 ago 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub… |
| CVE-2026-60007 | Crítica (9.1) | 0.55% | — | 4 ago 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a… |
| CVE-2026-58080 | Alta (8.8) | 0.38% | — | 4 ago 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`,… |
| CVE-2022-25897 | Alta (7.5) | 1.3% | — | 8 sept 2022 | The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the… |
| CVE-1999-0459 | Media (4.6) | 0.36% | — | 1 feb 1999 | Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.