Executive brief
A security flaw exists in the S2OPC library, which is used for secure industrial communications (OPC UA). The software fails to properly check all lists of revoked security certificates, potentially allowing a device or user with a cancelled certificate to maintain a connection to the server. This could lead to unauthorized access or the continued operation of compromised devices that should have been blocked from the network.
Technical details
The vulnerability is classified as an improper check for certificate revocation (CWE-299) within the `crt_verifycrl_and_check_revocation` function of the S2OPC CycloneCrypto wrapper. The implementation incorrectly terminates its search after finding the first matching CRL for a Certificate Authority, ignoring subsequent valid CRLs that may contain the certificate's revocation status. An attacker using a revoked certificate could successfully establish or maintain an OPC UA connection if the revocation entry exists in a CRL not processed by the library. The issue was identified in commit a442f472 and requires a fix to iterate through all associated CRLs to ensure comprehensive revocation verification.
Affected products
- Systerel S2OPC a442f47200aaf3e58194b209e0738a4f9056393a
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory