ICSA-14-135-04
·
Published 2025-06-09
·
View on CISA ICS-CERT ↗
Unified Automation OPC SDK OpenSSL Vulnerability
CVSS 7.5
HIGH
CISA KEV — Known Exploited
CVEs (1)
Remediations
- Disable HTTPS transport by configuration in the C++ SDK (default)
- Recompile the SDK without HTTPs Support (default)
- Download the current version of OpenSSL (http://www.openssl.org/)
Affected Vendors
Unified Automation
Affected Products (2)
Unified Automation
·
C++ based OPC UA SDK
V1.4.0_Windows
Unified Automation
·
ANSI C based OPC UA SDK
V1.4.0_Windows
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more