Skip to main navigation Skip to main content Skip to page footer

Unable to establish OPC DA connection after installing patch for CVE-2021-26414

Security Advisories IBA-2022-02

Grüner Hintergrund mit kreisförmigem digitalem Interface-Design.
Publishing Date 23.03.2022
Last Update 23.03.2022
Tracking IDIBA-2022-02
CVECVE-2021-26414
CVSS Base Score4.8
CVSS Temporal Score4.2
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C

Summary

Microsoft is releasing multiple updates that address CVE-2021-26414. This will increase the minimum authentication level of DCOM connections to packet integrity. OPC-DA also known as OPC Classic uses DCOM to establish connections and is therefore affected by this change. This means that any OPC Classic client that doesn't support the authentication level packet integrity and relies on DCOM will not be able to connect to remote OPC Classic servers after the DCOM security update is enforced.

The vulnerability is addressed by Microsoft in a phased rollout:

1. June 8, 2021: Initial deployment of update package - Customers can verify their applications.
2. June 14, 2022: Hardening of DCOM servers is enabled programmatically by default, but can be disabled via registry key.
3. March 14, 2023: Enables hardening of DCOM servers by default and the ability to disable the hardening is removed.

A detailed description of the timeline and the registry keys along with new DCOM error events, can be found in the Knowledge Base article KB5004442.

Affected products

ibaPDA
All versions prior to v7.3.11
In ibaPDA v7.3.11 the default authentication level was raised to packet integrity (5), in earlier versions it was set to connect (2).

How do I know that I'm affected

Check the version number in the title of the status application on the system where the server is running.

Solution

Update to ibaPDA Version v7.3.11 or higher.

Customer Actions

Update to ibaPDA Version v7.3.11 or higher to be able to connect to OPC DA servers which have set their authentication level to packet integrity.

Technical Details

Resources

1. Microsoft MSRC
2. KB5004442 - Manage changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414)
3. Common Vulnerabilities and Exposures - CVE-2021-26414
4. NIST - NATIONAL VULNERABILITY DATABASE

Timeline

2021-06-08Initial information published by Microsoft MSRC
2021-12-09Support ticket
2021-12-10Investigation which products are affected
2022-01-04Testing phase
2022-02-08New ibaPDA Version v7.3.11 released
2022-03-23Security advisory published
Zurück zur Übersicht

Was möchten Sie heute machen?

Mit der Auswahl des Landes wird meine Anfrage an die zuständige Landesniederlassung der iba AG für Vertrieb und Support weitergeleitet.Datenschutz­erklärung