Skip to main content

Security Advisory IBA-2022-02

Unable to establish OPC DA connection after installing patch for CVE-2021-26414

Publishing Date:2022-03-23
Last Update:2022-03-23
Tracking ID:IBA-2022-02
CVE:CVE-2021-26414
CVSS Base Score:4.8
CVSS Temporal Score:4.2
CVSS v3 Vector:CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C

Summary

Microsoft is releasing multiple updates that address CVE-2021-26414. This will increase the minimum authentication level of DCOM connections to packet integrity. OPC-DA also known as OPC Classic uses DCOM to establish connections and is therefore affected by this change. This means that any OPC Classic client that doesn't support the authentication level packet integrity and relies on DCOM will not be able to connect to remote OPC Classic servers after the DCOM security update is enforced.

The vulnerability is addressed by Microsoft in a phased rollout:

1. June 8, 2021: Initial deployment of update package - Customers can verify their applications.
2. June 14, 2022: Hardening of DCOM servers is enabled programmatically by default, but can be disabled via registry key.
3. March 14, 2023: Enables hardening of DCOM servers by default and the ability to disable the hardening is removed.

A detailed description of the timeline and the registry keys along with new DCOM error events, can be found in the Knowledge Base article KB5004442.

Affected products

ibaPDA
All versions prior to v7.3.11
In ibaPDA v7.3.11 the default authentication level was raised to packet integrity (5), in earlier versions it was set to connect (2).

How do I know that I'm affected

Check the version number in the title of the status application on the system where the server is running.

Customer Actions

Update to ibaPDA Version v7.3.11 or higher to be able to connect to OPC DA servers which have set their authentication level to packet integrity.

Timeline

2021-06-08 Initial information published by Microsoft MSRC
2021-12-09 Support ticket
2021-12-10 Investigation which products are affected
2022-01-04 Testing phase
2022-02-08 New ibaPDA Version v7.3.11 released
2022-03-23 Security advisory published
|Security Advisories Back