An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-08-30T19:00:00
Updated: 2024-08-05T18:28:15.650Z
Reserved: 2017-07-31T00:00:00
Link: CVE-2017-12069
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-08-30T19:29:00.210
Modified: 2024-11-21T03:08:46.230
Link: CVE-2017-12069
Redhat
No data.