An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-08-30T19:00:00

Updated: 2024-08-05T18:28:15.650Z

Reserved: 2017-07-31T00:00:00

Link: CVE-2017-12069

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-08-30T19:29:00.210

Modified: 2017-10-06T01:29:00.443

Link: CVE-2017-12069

cve-icon Redhat

No data.