Credential replay affecting those connected to a server when all 3 of the following conditions are met:
SecurityPolicy is NoneThe problem has been patched in version 0.3.6. A more relaxed treatment of validation as agreed upon by the OPC UA Security Working Group is implemented in version 0.3.7.
Do not use username/password or X509-based authentication with SecurityPolicy of None.
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-330",
"CWE-522"
],
"github_reviewed": true,
"github_reviewed_at": "2020-03-16T20:59:53Z",
"nvd_published_at": "2020-03-16T16:15:00Z",
"severity": "HIGH"
}