CVE-2025-7390

9.1

Softing · OPC UA C++ SDK, edgeConnector, edgeAggregator

A flaw in Softing OPC UA products allows unauthenticated attackers to bypass client certificate trust checks, potentially compromising secure communications.

Executive summary

A critical vulnerability in Softing industrial software allows unauthenticated attackers to bypass essential certificate trust validation, risking unauthorized data access.

Vulnerability

This is an improper certificate validation vulnerability (CWE-295) occurring in the opc.https server configuration. The flaw allows an unauthenticated remote attacker to bypass trust checks, effectively neutralizing the security provided by secure communication protocols.

Business impact

The ability for an attacker to bypass certificate validation compromises the integrity and confidentiality of the industrial communication channel. Given the CVSS score of 9.1, this vulnerability poses a severe risk of unauthorized access to sensitive operational data, potentially leading to process disruption or unauthorized control commands within industrial environments.

Remediation

Immediate Action: Update Softing OPC UA C++ SDK to version 6.80.1 or later, and transition edgeConnector/edgeAggregator to the SDEX Suite V1.0 or later.

Proactive Monitoring: Monitor network traffic for anomalous OPC UA connections and audit server access logs for unauthorized authentication attempts.

Compensating Controls: Implement network segmentation to isolate industrial servers from untrusted networks and utilize an industrial-grade firewall to restrict access to authorized clients only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant threat to industrial control systems by subverting the core security mechanism of certificate-based authentication. Organizations utilizing these Softing products must prioritize the transition to the specified patched versions immediately to prevent potential unauthorized access and maintain the integrity of their operational networks.