Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a vulnerability in Eclipse Milo, an implementation of the OPC Unified Architecture (OPC UA) protocol. The flaw allows an attacker on the same network to potentially recover user passwords and gain unauthorized access by exploiting how the system handles errors during authentication. While this technology is often used in industrial environments, its exposure to external networks can vary, making it important to confirm if your specific deployment is reachable.
- Authentication errors reveal password recovery methods.
- Protects industrial systems from network attackers.
- Confirm system exposure and validate controls.
Attack Path
How an attacker could exploit the issue
An attacker on the network can intercept a user's authentication token and repeatedly send unauthenticated requests. By observing the different error messages, the attacker can deduce information about the encrypted password and eventually recover it to gain unauthorized access.
- Requires network access to intercept traffic.
- Triggered by unauthenticated `ActivateSession` requests.
- Risk of password recovery and unauthorized access.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an on-path attacker could exploit a padding oracle vulnerability in username-token processing. This could allow them to recover a victim's password and subsequently authenticate as that victim.
- Victim password may be exposed.
- Attacker intercepts and replays requests.
- Unauthorized access to services.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects applications using Eclipse Milo for username-token authentication. The immediate priority is for infrastructure and platform teams to identify all deployments of this software. Once located, confirm the specific applications' exposure and criticality to inform the prioritization of remediation efforts, engaging application owners and potentially vendor management if the software is part of a commercial offering.
- Identify affected systems and owners.
- Verify exposure and business criticality.
- Plan remediation based on risk.