Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.
Solution:
Workaround:
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-349-01 | patch third party advisory us government resource |
https://www.prosysopc.com/blog/#Security | vendor advisory |