View Issue Details

IDProjectCategoryView StatusLast Update
000987410000-002: SecuritySpecpublic2025-04-01 15:21
ReporterRandy Armstrong Assigned ToFrank Volkmann  
PrioritynormalSeveritymajorReproducibilityalways
Status assignedResolutionopen 
Target Version1.05.05 RC1 
Summary0009874: Need to Address ARP Poisoning and Spanning Tree Protocol (STP) attacks
Description

ARP Poisoning and STP attack are well known vulnerabilities that affect all IP networks. Modern commercial routers have protections built in but they must be configured.

To protect against misconfiguration or routers that lack the protections, applications should encrypt all messages.

Need update to: 4.3 Security threats to OPC UA systems
and
5.1 Reconciliation of threats with OPC UA security mechanisms

Tagssg.Security
Commit Version1.05.06 RC1
Fix Due Date2025-05-15

Relationships

related to 0009875 closedRandy Armstrong 10000-007: Profiles Update Profile to require that SignOnly mode be disabled by default. 

Activities

Randy Armstrong

2024-10-09 15:17

administrator   ~0021872

Add profile that sign-only disable default.

Issue History

Date Modified Username Field Change
2024-10-09 14:17 Randy Armstrong New Issue
2024-10-09 15:17 Randy Armstrong Note Added: 0021872
2024-10-09 15:22 Randy Armstrong Issue cloned: 0009875
2024-10-09 15:23 Randy Armstrong Relationship added related to 0009875
2025-04-01 15:20 Jim Luth Tag Attached: sg.Security
2025-04-01 15:20 Jim Luth Assigned To => Frank Volkmann
2025-04-01 15:20 Jim Luth Status new => assigned
2025-04-01 15:20 Jim Luth Commit Version => 1.05.06 RC1
2025-04-01 15:20 Jim Luth Fix Due Date => 2025-05-15