CVE-2025-7390 Bypass the client certificate trust check of an opc.https server while only secure communication is allowed A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
Problem: CWE-295 Improper Certificate Validation
CWE-295 Impact: CAPEC-115 Authentication Bypass
CAPEC-115 | Product | Affected | Unaffected |
|---|
Softing OPC UA C++ SDK » opc.https server on Windows, Linux, VxWorks package repo Default status is unaffected | from 6.40 through 6.80
| |
| 6.80.1
|
Softing edgeConnector on Linux package repo Default status is affected | through 2025.03
| |
| SDEX Suite V1.0
|
Softing edgeAggregator on Linux package repo Default status is affected | through 2025.03
| |
| SDEX Suite V1.0
|
CPE Applicability:
CPE Applicability (based on the Affected products section)
-
- cpe:2.3:a:softing:opc_ua_c_sdk:*:*:windows:*:*:*:*:* is vulnerable from (including) 6.40 and up to (including) 6.80
- OR cpe:2.3:a:softing:opc_ua_c_sdk:*:*:linux:*:*:*:*:* is vulnerable from (including) 6.40 and up to (including) 6.80
- OR cpe:2.3:a:softing:opc_ua_c_sdk:*:*:vxworks:*:*:*:*:* is vulnerable from (including) 6.40 and up to (including) 6.80
- OR cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:windows:*:*:*:*:* is not vulnerable
- OR cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:linux:*:*:*:*:* is not vulnerable
- OR cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:vxworks:*:*:*:*:* is not vulnerable
- or
- cpe:2.3:a:softing:edgeconnector:*:*:linux:*:*:*:*:* is vulnerable from (including) 0 and up to (including) 2025.03
- OR cpe:2.3:a:softing:edgeconnector:sdex_suite_v1.0:*:linux:*:*:*:*:* is not vulnerable
- or
- cpe:2.3:a:softing:edgeaggregator:*:*:linux:*:*:*:*:* is vulnerable from (including) 0 and up to (including) 2025.03
- OR cpe:2.3:a:softing:edgeaggregator:sdex_suite_v1.0:*:linux:*:*:*:*:* is not vulnerable
SolutionOPC UA C++ SDK V6.80.1 Service-Patch
edgeAggregator & edgeConnector are now integrated in SDEX Suite: fix with V1.0