Skip to main navigation Skip to main content Skip to page footer

ibaPDA OPC UA server allowed in some cases connections with untrusted certificates

Security Advisories IBA-2022-01

Grüner Hintergrund mit kreisförmigem digitalem Interface-Design.
Publishing Date 08.03.2022
Last Update 08.03.2022
Tracking IDIBA-2022-01
CVSS Base Score4.2
CVSS VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Summary

Due to a bug in the used OPC UA Library < v1.4.368 it was possible in some cases, that an OPC UA client could establish a connection with an untrusted or expired certificate. If the OPC UA Server exposed writable tags, these could then be modified by the connected client.

Affected products

ibaPDA
All versions prior to v7.3.12

How do I know that I'm affected

Check the version number of the installed product in the About dialog which can be found in the Help menu.

Solution

Update to ibaPDA v7.3.12 or higher.

Customer Actions

Please install ibaPDA v7.3.12 or higher.

Technical Details

Issue

The used certificate validator was overridden in some cases, leading to an unsafe situation where any client with expired or untrusted certificate could establish a connection. A more detailed description can be found on GitHub #1711.

Timeline

2022-02-16Issue reported to OPC Foundation
2022-02-17Issue fixed by OPC Foundation
2022-03-07New ibaPDA Version released
2022-03-08Security advisory published
Zurück zur Übersicht

Was möchten Sie heute machen?

Mit der Auswahl des Landes wird meine Anfrage an die zuständige Landesniederlassung der iba AG für Vertrieb und Support weitergeleitet.Datenschutz­erklärung