6.4
CVSSv2

CVE-2017-12069

Published: 30/08/2017 Updated: 06/10/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code prior to 2017-03-21 and Local Discovery Server (LDS) prior to 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and previous versions), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens wincc

siemens simatic pcs7

ocpfoundation ua .net

ocpfoundation local discovery server