PT-2026-103051 · Apache · Apache Plc4X
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Apache PLC4X versions 0.9.0 through 0.13.1
Description
Improper verification of cryptographic signatures and improper certificate validation in the OPC UA driver (PLC4J) allow a network attacker to impersonate the OPC UA server. This enables the attacker to read, forge, or modify secure-channel traffic, including user credentials sent by the client. In versions 0.9.0 through 0.11.0, failed message-signature checks are only logged without enforcement, and server certificates are taken from unauthenticated GetEndpoints discovery responses. In versions 0.12.0 through 0.13.1, the signature check is inverted, accepting invalid signatures while rejecting valid ones, and server certificates are accepted without a trust anchor by default. Additionally, the default security policy is None across all affected versions; versions 0.12.0 and later may silently continue with a weaker security policy than configured, and version 0.13.0 prefers the weakest matching endpoint during selection.
Recommendations
Upgrade Apache PLC4X to version 1.0.0.
Fix
Improper Verification of Cryptographic Signature
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Plc4X