{"document":{"category":"opc_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"The information provided in this disclosure is provided 'as is' without warranty of any kind. OPC Foundation disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall OPC Foundation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if OPC Foundation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply"}],"publisher":{"category":"vendor","name":"OPC Foundation","namespace":"https://opcfoundation.org/security/csaf"},"references":[{"category":"self","summary":"Advisory Source","url":"https://github.com/OPCFoundation/SecurityAdvisories/tree/latest/csaf/2026/003"},{"category":"external","summary":"Mantis Issue","url":"https://mantis.opcfoundation.org/view.php?id=10055"},{"category":"external","summary":"A Comprehensive Formal Security Analysis of OPC UA","url":"https://eprint.iacr.org/2025/148"}],"title":"Security Update for the OPC UA Specification","tracking":{"current_release_date":"2026-09-15T00:00:00Z","id":"OPC-2026-08-12-003","initial_release_date":"2026-08-12T00:00:00Z","revision_history":[{"date":"2026-08-12T00:00:00Z","number":"1.0.0","summary":"Advisory created."},{"date":"2026-09-15T00:00:00Z","number":"1.0.1","summary":"Added note on reporter/vendor disagreement."}],"status":"release","version":"1.0.1"}},"product_tree":{"branches":[{"category":"product_name","name":"OPC UA Specification Part 4 - Services","product":{"name":"OPC UA Specification Part 4 - Services <1.05.07","product_id":"CSAFPID-04","product_identification_helper":{"skus":["OPC 10000-4"]}}},{"category":"product_name","name":"OPC UA Specification Part 6 - Mappings","product":{"name":"OPC UA Specification Part 6 - Mappings <1.05.07","product_id":"CSAFPID-06","product_identification_helper":{"skus":["OPC 10000-6"]}}}]},"vulnerabilities":[{"acknowledgments":[{"names":["Vincent Diemunsch"],"organization":"ANSSI & Inria, France"},{"names":["Lucca Hirschi"],"organization":"Inria, France"},{"names":["Steve Kremer"],"organization":"Inria, France","summary":"For discovering the issue using the ProVerif protocol analyzer, see eprint https://eprint.iacr.org/2025/148."}],"cwe":{"id":"CWE-294","name":"Authentication Bypass by Capture-replay"},"discovery_date":"2024-08-10T00:00:00Z","ids":[{"system_name":"GCVE","text":"GCVE-105-2026-003"}],"involvements":[{"date":"2026-03-01T00:00:00Z","party":"vendor","status":"completed"}],"notes":[{"category":"other","text":"The CVSS v3.1 score published here uses Scope:Unchanged (S:U): 5.9 (MEDIUM). The reporters assess Scope:Changed (S:C): 7.7 (HIGH). The disagreement concerns only the Scope metric. Reporter position: OPC UA secure-channel security (UA-SC/PKI) and session-and-user authentication are two distinct security authorities, each with its own certificate exchange and potentially implemented as separate components or processes; the attack chains a channel-layer key compromise into a session/user-identity compromise, crossing from one authority to the other, which the reporters consider a scope change. OPC Foundation position: the impacted resources (the Server's nodes, address space, and operations) are governed by exactly one security authority which evaluates the client certificate, the endpoint used, the user token, and other configured criteria as inputs to a single access-control decision applied on every operation (OPC 10000-18 4.4). The SecureChannel and PKI authenticate endpoints; they do not define or enforce which operations a subject may perform on Server resources. A separable implementation is not a separate security authority; CVSS Scope concerns authorization domains, not library, process, or code boundaries. The attack is a horizontal move to impersonate another user to the same Server and reach that Server's resources, which is the standard Scope:Unchanged pattern.","title":"CVSS Scope Assessment (vendor / reporter disagreement)"}],"references":[{"summary":"CWE-294: Authentication Bypass by Capture-replay","url":"https://cwe.mitre.org/data/definitions/294.html"}],"remediations":[{"category":"vendor_fix","details":"OPC UA Part 4 - Services 1.05.07 §6.1.8: Defines new calculations for user token signatures which prevent re-use of tokens.","product_ids":["CSAFPID-04"],"url":"https://reference.opcfoundation.org/Core/Part4/v105/docs/6.1.8"},{"category":"vendor_fix","details":"OPC UA Part 6 - Mappings 1.05.07 §6.7.5: Defines a unique identifier associated with a secure channel.","product_ids":["CSAFPID-06"],"url":"https://reference.opcfoundation.org/Core/Part6/v105/docs/6.7.5"},{"category":"mitigation","details":"Following the OPC UA guidelines on managing private keys would reduce the likelyhood that the prerequisites can be met. Specifically, protect Client and Server private keys in hardware or a secure element where feasible and enforce strict decommissioning of retired keys; rotate private keys regularily; prefer SignAndEncrypt over Sign on exposed endpoints; and segment the network so that the traffic interception this attack requires is not available from general network positions.","product_ids":["CSAFPID-04","CSAFPID-06"]}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C","version":"3.1"},"products":["CSAFPID-04","CSAFPID-06"]}],"threats":[{"category":"impact","details":"An attacker can re-use a certificate user identity sent over a different secure channel and bypass authentication and authorization mechanisms for a server."},{"category":"target_set","details":"The attacker has access to the private key of a client, the private key of the server, and must be able to intercept network traffic sent by that client."}],"title":"If private keys of a client and server are compromised, an attacker may re-use a certificate user identity sent over a different secure channel."}]}