PT-2026-103051 · Apache · Apache Plc4X

·

CVE-2026-102508

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Apache PLC4X versions 0.9.0 through 0.13.1
Description Improper verification of cryptographic signatures and improper certificate validation in the OPC UA driver (PLC4J) allow a network attacker to impersonate the OPC UA server. This enables the attacker to read, forge, or modify secure-channel traffic, including user credentials sent by the client. In versions 0.9.0 through 0.11.0, failed message-signature checks are only logged without enforcement, and server certificates are taken from unauthenticated GetEndpoints discovery responses. In versions 0.12.0 through 0.13.1, the signature check is inverted, accepting invalid signatures while rejecting valid ones, and server certificates are accepted without a trust anchor by default. Additionally, the default security policy is None across all affected versions; versions 0.12.0 and later may silently continue with a weaker security policy than configured, and version 0.13.0 prefers the weakest matching endpoint during selection.
Recommendations Upgrade Apache PLC4X to version 1.0.0.

Fix

Improper Verification of Cryptographic Signature

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102508

Affected Products

Apache Plc4X