目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-102508— Apache PLC4X OPC UA 安全通道完整性绕过漏洞

一分钟漏洞结论

影响对象
Apache Software Foundation Apache PLC4X
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Apache PLC4X(PLC4J)中的 OPC UA 驱动存在加密签名验证不当和证书验证不当的漏洞,使得处于客户端与服务器之间网络位置的攻击者能够冒充 OPC UA 服务器,并读取、伪造或修改安全通道中的流量(包括客户端发送的用户凭据)。 该缺陷在不同版本中表现不同: 在 0.9.0 至 0.11.0 版本中,消息签名校验失败仅被记录日志,从未强制执行;且不存在验证服务器证书的机制:证书直接取自未经身份验证的 GetEndpoints 发现响应,并用于加密用户密码。 在 0.12.0 至 0.13.1 版本中,

CVSS 9.2 · Critical
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-102508 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
来源: CVE Program / CVE List V5
Vulnerability Description
Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client. The defect manifests differently depending on the version: - In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password. - In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default. - In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint. Users checking only for one of these mechanisms may wrongly conclude they are unaffected. This issue affects Apache PLC4X: from 0.9.0 before 1.0.0. Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the connection if the negotiated security policy is weaker than the configured one.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Apache Software Foundation Apache PLC4X 0.9.0 ~ 1.0.0 -

二、漏洞 CVE-2026-102508 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-102508 的情报信息

请登录查看更多情报信息。

CVE-2026-102508 邮件列表归档 (1)

同批安全公告 · Apache Software Foundation · 2026-09-30 · 共 19 条

CVE-2026-94052 9.1 CRITICAL Apache MINA SSHD LDAP认证失效漏洞
CVE-2026-94053 9.1 CRITICAL Apache MINA SSHD LDAP注入漏洞
CVE-2026-77185 9.1 CRITICAL Apache MINA SSHD 异步认证绕过签名验证漏洞
CVE-2026-102509 8.7 HIGH Apache PLC4X OPC UA驱动认证前资源耗尽漏洞
CVE-2026-102510 8.7 HIGH Apache PLC4X Go绑定远程内存耗尽漏洞
CVE-2026-102511 8.5 HIGH Apache PLC4X ADS发现响应欺骗漏洞
CVE-2026-93994 8.1 HIGH Apache MINA SSHD 公钥策略绕过漏洞
CVE-2026-94002 7.5 HIGH Apache MINA SSHD 内存耗尽漏洞
CVE-2026-93995 6.5 MEDIUM Apache MINA SSHD 远程代码执行漏洞
CVE-2026-93996 6.5 MEDIUM Apache MINA SSHD 内存耗尽拒绝服务漏洞
CVE-2026-94029 6.5 MEDIUM Apache MINA SSHD SFTP内存耗尽漏洞
CVE-2026-87830 Apache WSS4J 流式验证跳过元素保护检查漏洞
CVE-2026-85532 Apache WSS4J 派生密钥参数验证不足漏洞
CVE-2026-88920 Apache WSS4J SAML身份验证绕过漏洞
CVE-2026-89238 Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti
CVE-2026-92121 Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST
CVE-2026-92899 Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
CVE-2026-95616 Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5

IV. Related Vulnerabilities

V. Comments for CVE-2026-102508

暂无评论


发表评论