Impact
The vulnerability resides in node‑opcua’s UserNameIdentityToken authentication logic, which decrypts an RSA‑OAEP encoded password blob without verifying that the appended bytes match the current session’s serverNonce. An unauthenticated remote attacker can retrieve the server’s public key by calling GetEndpoints, craft a ciphertext whose little‑endian length resolves to an empty password, and have the server accept it during isValidUser, enabling compromise of any account that permits an empty password. The missing nonce binding also permits the forged token to be replayed in other sessions, and with SecurityMode set to None the additional client‑signature protection is absent, further easing the attack. The flaw is fixed in node‑opcua v2.166.0.
Affected Systems
Node-opcua v2.x for Node.js and TypeScript applications that use the UserNameIdentityToken authentication flow, particularly versions prior to 2.166.0. The vulnerability impacts any installation that accepts empty passwords and relies on node‑opcua’s server implementation located in packages/node‑opcua-server/source/opcua_server.ts.
Risk and Exploitability
The vulnerability scores a CVSS of 7.7, indicating a high risk of unauthorized access. The EPSS score is below 1%, and it is not listed in CISA’s KEV catalog, suggesting a low but non‑zero exploitation probability. Remote attackers can exploit the weakness by first querying GetEndpoints to obtain the server’s public key, then sending a specially crafted RSA‑OAEP blob that tricks the server into accepting an empty password. Because the nonce is not bound to the session, malicious tokens can be replayed across sessions, and the absence of client signatures when SecurityMode=None removes an important safeguard. Given the potential for account takeover and the ease of exploitation, remediation should be treated as urgent.
OpenCVE Enrichment
Github GHSA