An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367
Published Aug 30, 2017
8.2
HIGHCVSS 3.0
EPSS 2.90%
Description
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
Affected products
No data.
Configuration 1
- ≤ 8.1
- ≤ 7.4
Configuration 2
- ≤ 1.01.333.0
- ≤ 2017-03-21
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- http://www.securityfocus.com/bid/100559 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039510 vdb-entryx_refsource_SECTRACK
- https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2017-12069.pdf x_refsource_CONFIRMPatchVendor Advisory
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-535640.pdf x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/100559 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1039510 | vdb-entryx_refsource_SECTRACK | |
| https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2017-12069.pdf | x_refsource_CONFIRMPatchVendor Advisory | |
| https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-535640.pdf | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.