Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mq36-523m-x7vv",
"modified": "2026-08-20T18:35:33Z",
"modified": "2026-08-20T18:36:02Z",
"published": "2026-08-20T18:35:33Z",
"aliases": [
"CVE-2026-54155"
],
"summary": "node-opcua missing nonce verification in UserNameIdentityToken authentication",
"details": "**Summary**\nA missing nonce verification in the UserNameIdentityToken authentication handler allows an unauthenticated remote attacker to forge a password token that extracts as an empty string, and to replay captured authentication tokens across sessions.\n\n**Affected versions:** <= 2.165.0\n**Tested version:** 2.165.0\n**CVSS Score:** 8.1 (High)\n**CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L\n**CWE:** CWE-347 Improper Verification of Cryptographic Signature\n\n---\n\n**Root Cause**\n\nIn `packages/node-opcua-server/source/opcua_server.ts` at line 1886-1887, after RSA-OAEP decrypting the UserNameIdentityToken password blob, the server reads a 4-byte little-endian length field and extracts `buff[4 : 4+length]` as the password. It never verifies that the trailing bytes equal `session.nonce`.\n\nThis has two consequences:\n\n1. **Forged empty password:** An attacker who retrieves the server's public key via an unauthenticated `GetEndpoints` call can craft a token where the 4-byte length field equals `serverNonce.length` (32). The server computes `length = 32 - 32 = 0` and calls `isValidUser(username, \"\")`. Any account that accepts an empty password is compromised.\n\n2. **Unconditional replay attack:** Because nonce binding is structurally absent, any captured UserNameIdentityToken ciphertext can be replayed in a different session unconditionally.\n\nThe impact is compounded by a second issue: when the channel uses `SecurityMode=None`, `verifyClientSignature` returns `true` unconditionally (security_policy.ts:697-700), bypassing the channel-level signature check entirely.\n\n---\n\n**Proof of Concept (logic, no exploit code)**\n\n```\n1. GetEndpoints (unauthenticated) → retrieve server public key and RSA token policy\n2. OpenSecureChannel (SecurityMode=None)\n3. CreateSession\n4. Craft plaintext: [0x20, 0x00, 0x00, 0x00] (readUInt32LE = 32 = serverNonce.length)\n5. RSA-OAEP encrypt with server public key → 256-byte ciphertext\n6. ActivateSession with crafted UserNameIdentityToken\n7. Server decrypts → length = 32 - 32 = 0 → password = \"\"\n8. isValidUser(username, \"\") is called\n```\n\nDynamically confirmed: decryption produces `password = \"\"` with no error and no nonce verification.\n\n---\n\n**Suggested Fix**\n\nAfter decrypting the password blob, verify that `buff.slice(4 + passwordLength)` equals `session.nonce` before extracting the password. Reject the token if verification fails.\n\n---\n\nI am following a 90-day responsible disclosure policy. I am happy to provide additional technical details under embargo. Please confirm receipt at your earliest convenience.\n\nReporter: Stanley Tobias\nDiscovery date: 2026-03-23",
"details": "**Summary**\nA missing nonce verification in the UserNameIdentityToken authentication handler allows an unauthenticated remote attacker to forge a password token that extracts as an empty string, and to replay captured authentication tokens across sessions.\n\n**Affected versions:** < 2.166.0\n**Tested version:** 2.165.0\n**CVSS Score:** 8.1 (High)\n**CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L\n**CWE:** CWE-347 Improper Verification of Cryptographic Signature\n\n---\n\n**Root Cause**\n\nIn `packages/node-opcua-server/source/opcua_server.ts` at line 1886-1887, after RSA-OAEP decrypting the UserNameIdentityToken password blob, the server reads a 4-byte little-endian length field and extracts `buff[4 : 4+length]` as the password. It never verifies that the trailing bytes equal `session.nonce`.\n\nThis has two consequences:\n\n1. **Forged empty password:** An attacker who retrieves the server's public key via an unauthenticated `GetEndpoints` call can craft a token where the 4-byte length field equals `serverNonce.length` (32). The server computes `length = 32 - 32 = 0` and calls `isValidUser(username, \"\")`. Any account that accepts an empty password is compromised.\n\n2. **Unconditional replay attack:** Because nonce binding is structurally absent, any captured UserNameIdentityToken ciphertext can be replayed in a different session unconditionally.\n\nThe impact is compounded by a second issue: when the channel uses `SecurityMode=None`, `verifyClientSignature` returns `true` unconditionally (security_policy.ts:697-700), bypassing the channel-level signature check entirely.\n\n---\n\n**Proof of Concept (logic, no exploit code)**\n\n```\n1. GetEndpoints (unauthenticated) → retrieve server public key and RSA token policy\n2. OpenSecureChannel (SecurityMode=None)\n3. CreateSession\n4. Craft plaintext: [0x20, 0x00, 0x00, 0x00] (readUInt32LE = 32 = serverNonce.length)\n5. RSA-OAEP encrypt with server public key → 256-byte ciphertext\n6. ActivateSession with crafted UserNameIdentityToken\n7. Server decrypts → length = 32 - 32 = 0 → password = \"\"\n8. isValidUser(username, \"\") is called\n```\n\nDynamically confirmed: decryption produces `password = \"\"` with no error and no nonce verification.\n\n---\n\n**Suggested Fix**\n\nAfter decrypting the password blob, verify that `buff.slice(4 + passwordLength)` equals `session.nonce` before extracting the password. Reject the token if verification fails.\n\n---\n\nI am following a 90-day responsible disclosure policy. I am happy to provide additional technical details under embargo. Please confirm receipt at your earliest convenience.\n\nReporter: Stanley Tobias\nDiscovery date: 2026-03-23",
"severity": [
{
"type": "CVSS_V3",
Expand All @@ -28,7 +28,7 @@
"introduced": "0"
},
{
"last_affected": "2.165.0"
"fixed": "2.166.0"
}
]
}
Expand Down
Loading