Impact
Apache PLC4X’s OPC UA driver fails to enforce or incorrectly verifies cryptographic signatures and server certificates. An attacker positioned between client and server can impersonate the OPC UA server, read, forge, or alter secure‑channel traffic, including credentials sent by the client. The flaw spans multiple versions and exposes clients to man‑in‑the‑middle attacks and data tampering.
Affected Systems
Apache Software Foundation’s PLC4X package versions 0.9.0 through 0.11.0, 0.12.0 through 0.13.1, and any release prior to 1.0.0 are vulnerable. All affected distributions use the default security policy ‘None’, and the driver may silently downgrade to a weaker policy or accept unverified certificates.
Risk and Exploitability
The vulnerability has a CVSS score of 9.2 and is not listed in the CISA KEV catalog. Because the EPSS score is not available, a precise exploitation likelihood cannot be quantified but the flaw permits a network attacker between the PLC client and server to intercept and modify traffic. The attack vector is inferred to be remote, exploiting the lack of signature enforcement and certificate validation during the secure‑channel establishment.
OpenCVE Enrichment