Apache PLC4X(PLC4J)中的 OPC UA 驱动存在加密签名验证不当和证书验证不当的漏洞,使得处于客户端与服务器之间网络位置的攻击者能够冒充 OPC UA 服务器,并读取、伪造或修改安全通道中的流量(包括客户端发送的用户凭据)。 该缺陷在不同版本中表现不同: 在 0.9.0 至 0.11.0 版本中,消息签名校验失败仅被记录日志,从未强制执行;且不存在验证服务器证书的机制:证书直接取自未经身份验证的 GetEndpoints 发现响应,并用于加密用户密码。 在 0.12.0 至 0.13.1 版本中,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache PLC4X | 0.9.0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94052 | 9.1 CRITICAL | Apache MINA SSHD: LDAP password authentication ineffective |
| CVE-2026-94053 | 9.1 CRITICAL | Apache MINA SSHD: LDAP injection in sshd-ldap |
| CVE-2026-77185 | 9.1 CRITICAL | Apache MINA SSHD: Asynchronous authentication can bypass signature verification |
| CVE-2026-102509 | 8.7 HIGH | Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an |
| CVE-2026-102510 | 8.7 HIGH | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len |
| CVE-2026-102511 | 8.5 HIGH | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp |
| CVE-2026-93994 | 8.1 HIGH | Apache MINA SSHD: Repeated-publickey policy bypass on server |
| CVE-2026-94002 | 7.5 HIGH | Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies |
| CVE-2026-93995 | 6.5 MEDIUM | Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser |
| CVE-2026-93996 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read |
| CVE-2026-94029 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension |
| CVE-2026-87830 | Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks. | |
| CVE-2026-85532 | Apache WSS4J: Insufficient Validation of Derived-Key Parameters | |
| CVE-2026-88920 | Apache WSS4J: SAML Sender-Vouches Authentication Bypass | |
| CVE-2026-89238 | Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti | |
| CVE-2026-92121 | Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST | |
| CVE-2026-92899 | Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce | |
| CVE-2026-95616 | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5 |
No comments yet