Executive brief
A security flaw exists in S2OPC, an open-source implementation of the OPC UA communication protocol used in industrial automation. The software fails to properly check if a master security certificate has expired, which could allow unauthorized or outdated systems to be incorrectly trusted. This could potentially lead to unauthorized access or data manipulation within industrial control environments.
Technical details
An improper certificate validation vulnerability (CWE-295) exists in the CycloneCrypto cryptographic wrapper of S2OPC. The root cause is a failure to correctly verify the validity period of a root issuer certificate during the chain of trust validation. A remote attacker could potentially present a certificate signed by an expired or otherwise invalid root CA, which the system would incorrectly accept as trusted. This affects S2OPC versions 1.5.0 through 1.9.x and is addressed in version 2.0.0. Exploitation requires a high-complexity environment where the attacker can intercept or initiate network communication.
Affected products
- Systerel S2OPC >= 1.5.0, < 2.0.0
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory