csaf_opcfoundation:opc-2026-08-12-004

csaf_opcfoundation
Description

The information provided in this disclosure is provided 'as is' without warranty of any kind. OPC Foundation disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall OPC Foundation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if OPC Foundation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply

Timeline
Published
2026-08-12 00:00 UTC
Last Modified
2026-08-12
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "category": "opc_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "The information provided in this disclosure is provided 'as is' without warranty of any kind. OPC Foundation disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall OPC Foundation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if OPC Foundation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply"
      }
    ],
    "publisher": {
      "category": "vendor",
      "name": "OPC Foundation",
      "namespace": "https://opcfoundation.org/security/csaf"
    },
    "references": [
      {
        "category": "self",
        "summary": "Advisory Source",
        "url": "https://github.com/OPCFoundation/SecurityAdvisories/tree/latest/csaf/2026/004"
      },
      {
        "category": "external",
        "summary": "Mantis Issue",
        "url": "https://mantis.opcfoundation.org/view.php?id=9432"
      },
      {
        "category": "external",
        "summary": "A Comprehensive Formal Security Analysis of OPC UA",
        "url": "https://eprint.iacr.org/2025/148"
      }
    ],
    "title": "Informational Advisory for the OPC UA Specification",
    "tracking": {
      "current_release_date": "2026-08-12T00:00:00Z",
      "id": "OPC-2026-08-12-004",
      "initial_release_date": "2026-08-12T00:00:00Z",
      "revision_history": [
        {
          "date": "2026-08-12T00:00:00Z",
          "number": "1.0.0",
          "summary": "Advisory created."
        }
      ],
      "status": "release",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "product_name",
        "name": "OPC UA Specification Part 4 - Services",
        "product": {
          "name": "OPC UA Specification Part 4 - Services",
          "product_id": "CSAFPID-04",
          "product_identification_helper": {
            "skus": [
              "OPC 10000-4"
            ]
          }
        }
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Vincent Diemunsch"
          ],
          "organization": "ANSSI & Inria, France"
        },
        {
          "names": [
            "Lucca Hirschi"
          ],
          "organization": "Inria, France"
        },
        {
          "names": [
            "Steve Kremer"
          ],
          "organization": "Inria, France",
          "summary": "For discovering the issue using the ProVerif protocol analyzer, see eprint https://eprint.iacr.org/2025/148."
        }
      ],
      "cwe": {
        "id": "CWE-319",
        "name": "Cleartext Transmission of Sensitive Information"
      },
      "discovery_date": "2024-08-10T00:00:00Z",
      "ids": [
        {
          "system_name": "GCVE",
          "text": "GCVE-105-2026-004"
        }
      ],
      "involvements": [
        {
          "date": "2026-03-01T00:00:00Z",
          "party": "vendor",
          "status": "completed"
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "This item is published for the record as an informational advisory. No CVSS score and no vulnerability severity are assigned. The issue was reported by security researchers, however, the working group concluded that no normative change to the specification was needed. The specification already recommends that applications never set the SecurityPolicy to None for UserIdentityTokens that include a secret, and the exposure described depends on the compromise of the keys that protect the channel, a condition that applies to any protocol which carries a password inside an encrypted channel.",
          "title": "Disposition: Informational"
        }
      ],
      "references": [
        {
          "summary": "CWE-319: Cleartext Transmission of Sensitive Information",
          "url": "https://cwe.mitre.org/data/definitions/319.html"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "OPC UA Part 4 - Services §7.40.2.1: \"It is recommended that applications never set the SecurityPolicy to None for UserIdentityTokens that include a secret because these secrets could be used by an attacker to gain access to the system.\" Encrypting the user token with its own SecurityPolicy means the password is not exposed if the keys protecting the SecureChannel are compromised.",
          "product_ids": [
            "CSAFPID-04"
          ],
          "url": "https://reference.opcfoundation.org/Core/Part4/v105/docs/7.40.2.1"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "An attacker can decrypt packets and recover user passwords if secure channel keys are compromised."
        },
        {
          "category": "target_set",
          "details": "This is a hypothetical problem that applies to all encrypted communication that use simple password authentication (this includes almost all HTTPS applications)."
        }
      ],
      "title": "If the keys for any encrypted channel (OPC UA and non-OPC UA) are compromised, user passwords transmitted within the channel can be recovered."
    }
  ]
}
View JSON API Download JSON