Softing2025-08-14
CVE-2025-7390 Bypass the client certificate trust check of an opc.https server while only secure communication is allowed

A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.

Problem: CWE-295 Improper Certificate Validation CWE-295
Impact: CAPEC-115 Authentication Bypass CAPEC-115
ProductAffectedUnaffected
Softing OPC UA C++ SDK » opc.https server on Windows, Linux, VxWorks
package repo
Default status is unaffected
from 6.40 through 6.80
6.80.1
Softing edgeConnector on Linux
package repo
Default status is affected
through 2025.03
SDEX Suite V1.0
Softing edgeAggregator on Linux
package repo
Default status is affected
through 2025.03
SDEX Suite V1.0

CPE Applicability:

CPE Applicability (based on the Affected products section)

    • cpe:2.3:a:softing:opc_ua_c_sdk:*:*:windows:*:*:*:*:* is vulnerable from (including) 6.40 and up to (including) 6.80
    • OR cpe:2.3:a:softing:opc_ua_c_sdk:*:*:linux:*:*:*:*:* is vulnerable from (including) 6.40 and up to (including) 6.80
    • OR cpe:2.3:a:softing:opc_ua_c_sdk:*:*:vxworks:*:*:*:*:* is vulnerable from (including) 6.40 and up to (including) 6.80
    • OR cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:windows:*:*:*:*:* is not vulnerable
    • OR cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:linux:*:*:*:*:* is not vulnerable
    • OR cpe:2.3:a:softing:opc_ua_c_sdk:6.80.1:*:vxworks:*:*:*:*:* is not vulnerable
  • or
    • cpe:2.3:a:softing:edgeconnector:*:*:linux:*:*:*:*:* is vulnerable from (including) 0 and up to (including) 2025.03
    • OR cpe:2.3:a:softing:edgeconnector:sdex_suite_v1.0:*:linux:*:*:*:*:* is not vulnerable
  • or
    • cpe:2.3:a:softing:edgeaggregator:*:*:linux:*:*:*:*:* is vulnerable from (including) 0 and up to (including) 2025.03
    • OR cpe:2.3:a:softing:edgeaggregator:sdex_suite_v1.0:*:linux:*:*:*:*:* is not vulnerable


Solution

OPC UA C++ SDK V6.80.1 Service-Patch

edgeAggregator & edgeConnector are now integrated in SDEX Suite: fix with V1.0

References
industrial.softing.com/fileadmin/psirt/downloads/2025/CVE-2025-7390.html
industrial.softing.com/fileadmin/psirt/downloads/2025/CVE-2025-7390.json