Apache PLC4X versions from 0.9.0 up to, but not including, 1.0.0 are affected. Version 1.0.0 is listed as unaffected.
The attacker must be in a network position between the PLC4X OPC UA client and server. No privileges or user interaction are required.
Yes. The default security policy is None in all affected versions. In versions 0.12.0 through 0.13.1, the driver can also silently continue with a weaker security policy.
An attacker can impersonate the OPC UA server and read, forge, or modify secure-channel traffic. This includes user credentials sent by the client.
Upgrade to Apache PLC4X 1.0.0, which is listed as unaffected. Treat OPC UA connections over networks where an attacker could occupy an intermediary position as exposed until the affected client is replaced.