Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq4w-qm9g-qx68

Опубликовано: 16 мар. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Insufficient Nonce Validation in Eclipse Milo Client

Impact

Credential replay affecting those connected to a server when all 3 of the following conditions are met:

  • SecurityPolicy is None
  • using username/password or X509-based authentication
  • the server has a defect causing it to send null/empty or zeroed nonces

Patches

The problem has been patched in version 0.3.6. A more relaxed treatment of validation as agreed upon by the OPC UA Security Working Group is implemented in version 0.3.7.

Workarounds

Do not use username/password or X509-based authentication with SecurityPolicy of None.

References

https://opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2019-19135.pdf

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.eclipse.milo:sdk-client

maven
Затронутые версииВерсия исправления

<= 0.3.4

0.3.6

EPSS

Процентиль: 49%
0.00264
Низкий

7.4 High

CVSS3

Дефекты

CWE-330
CWE-522

Связанные уязвимости

CVSS3: 7.4
nvd
почти 6 лет назад

In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.

EPSS

Процентиль: 49%
0.00264
Низкий

7.4 High

CVSS3

Дефекты

CWE-330
CWE-522