Our takeCISA advisory ICSA-26-211-08 flags four flaws in o6 Automation open62541 (v1.3.0–1.3.17) on Windows and Linux that let attackers leak data, DoS the service, or run code. Patch if you run this OPC UA stack.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Patch open62541 to beyond 1.3.17 (or upgrade to 1.4.x) on any Windows or Linux systems in your OT/ICS environment. The four CVEs allow information disclosure, DoS, or arbitrary code execution.
What this means for you — Lean IT orgs:If you run any industrial equipment or automation software that uses open62541, check with your vendor or integrator immediately and apply the update to version 1.4 or newer.
What this means for you — MSP:Audit client OT/ICS estates for open62541 1.3.0–1.3.17 on Windows or Linux; prioritize patching or upgrading to 1.4.x where present.
What this means for you — Researcher:CISA ICSA-26-211-08 details four vulnerabilities in o6 Automation open62541 (1.3.0–1.3.17) that can lead to info disclosure, DoS, or RCE.