Impact
The vulnerability arises because Eclipse Milo OPC UA servers fail to enforce authorization on diagnostics nodes, allowing clients to enable diagnostics on a None/None endpoint without a certificate. When a trusted client presents a valid certificate under SignAndEncrypt, it can read detailed security diagnostics from other active sessions, which reveals usernames, login history, authentication mechanisms, security modes and policies, and public client certificates. This results in the disclosure of sensitive operational information to unauthorized parties.
Affected Systems
The affected products are Eclipse Foundation products under the Eclipse Milo project, specifically server implementations in versions ranging from 0.6.0 up to and including 1.1.4. No further vendor subcomponents are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity flaw, and an EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via an OPC UA endpoint that allows anonymous connection or a trusted client certificate. The scenario requires the attacker to access an OPC UA server exposed over the network and to have either an ability to connect anonymously or a valid application certificate; once connected, the attacker can query diagnostics nodes and retrieve confidential session information. Implications include compromised confidentiality of user credentials and system audit data.
OpenCVE Enrichment