logo

Utilities, Factories at Risk From Encryption Holes in Industrial Protocol

ID: da633a0c-f4a9-5b14-bbd4-baaa0f75de4f

STIX ID: report--da633a0c-f4a9-5b14-bbd4-baaa0f75de4f

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-08-11

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Research presented at DEF CON 33 revealed multiple cryptographic and protocol-design weaknesses in OPC UA (Open Platform Communications Unified Architecture) that can allow authentication bypass and misuse of signed messages; attacks include an HTTPS handshake bypass and exploitation of legacy PKCS#1 behavior, resulting in three disclosed CVEs and vendor patches or mitigation advisories. The issues affect several vendor implementations used in OT/industrial environments, and mitigations range from applying vendor updates and disabling vulnerable features (e.g., HTTPS variant or Basic128Rsa15) to using IP allowlisting and reviewing authentication configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.