FAQ Search Memberlist RSS Feed Register Profile Log in to check your private messages Log in
CERT security vulnerability reports

 
Post new topic   Reply to topic    OPC Foundation Message Board Forum Index -> Miscellaneous FAQ
View previous topic :: View next topic  
Author Message
Jim Luth



Joined: 18 Feb 2003
Posts: 168
Location: OPC Foundation

PostPosted: Wed Feb 28, 2007 5:09 pm    Post subject: CERT security vulnerability reports Reply with quote

I have seen some CERT security vulnerability notices for some OPC products. Is there a security flaw in the OPC interface? Do all OPC products have these vulnerabilities?
Back to top
View user's profile Send private message Visit poster's website
Jim Luth



Joined: 18 Feb 2003
Posts: 168
Location: OPC Foundation

PostPosted: Wed Feb 28, 2007 5:10 pm    Post subject: Reply with quote

Since the purpose of the OPC interface is to provide a well known standard way for software products from multiple vendors to communicate, the existence of such interfaces will always provide a possible attack surface for malicious applications to exploit. The vulnerabilities that have been reported by CERT[1] and others are for particular OPC implementations in vendor products and do not indicate any weakness in the design of the OPC interfaces themselves. In fact using one such vulnerability testing tool, the majority of OPC products tested passed[2]. It is also important to note that for such an attack to happen, the DCOM security would have to have been somehow breached (or have been misconfigured, i.e. turned off).

The OPC Foundation urges all OPC vendors to follow secure coding practices and be vigilant in testing their OPC implementations for security vulnerabilities.


[1] http://www.neutralbit.com/en/press/news/17/

[2] http://www.digitalbond.com/index.php/2007/01/29/s4-day-two-in-review/
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    OPC Foundation Message Board Forum Index -> Miscellaneous FAQ All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2002 phpBB Group