Utilities, Factories at Risk From Encryption Holes in Industrial Protocol
ID: da633a0c-f4a9-5b14-bbd4-baaa0f75de4f
STIX ID: report--da633a0c-f4a9-5b14-bbd4-baaa0f75de4f
Feed Name: Dark Reading
Research presented at DEF CON 33 revealed multiple cryptographic and protocol-design weaknesses in OPC UA (Open Platform Communications Unified Architecture) that can allow authentication bypass and misuse of signed messages; attacks include an HTTPS handshake bypass and exploitation of legacy PKCS#1 behavior, resulting in three disclosed CVEs and vendor patches or mitigation advisories. The issues affect several vendor implementations used in OT/industrial environments, and mitigations range from applying vendor updates and disabling vulnerable features (e.g., HTTPS variant or Basic128Rsa15) to using IP allowlisting and reviewing authentication configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
