CVE-2017-12069
published 2017-08-30CVE-2017-12069: An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the…
PriorityP347high8.2CVSS 3.0
AVNACLPRNUINSUCLINAH
EPSS
2.90%
85.3th percentile
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ocpfoundation | local_discovery_server | <= 1.01.333.0 | — |
| ocpfoundation | ua_net | <= 2017-03-21 | — |
| siemens | simatic_pcs7 | <= 8.1 | — |
| siemens | wincc | <= 7.4 | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj7f-wqmm-8q5f: An XXE vulnerability has been identified in OPC Foundation UA
ghsa_unreviewed·2022-05-17
CVE-2017-12069 [HIGH] CWE-611 GHSA-jj7f-wqmm-8q5f: An XXE vulnerability has been identified in OPC Foundation UA
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
CISA ICS
Siemens OPC UA Protocol Stack Discovery Service (Update E)
cisa_ics·2020-08-11·CVSS 8.2
[HIGH] Siemens OPC UA Protocol Stack Discovery Service (Update E)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens OPC UA Protocol Stack Discovery Service (Update E)
Last RevisedApril 14, 2022
Alert CodeICSA-17-243-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper restriction of XML external entity reference
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-17-243-01 Siemens OPC UA Protocol Stack Discovery Service (Update D) that was published August 11, 2020, on the on the ICS webpage on www.cisa.gov/uscert.
## 3
CISA ICS
Siemens industrial products using the Discovery Service of the OPC UA protocol stack by the OPC foundation
cisa_ics·2017-12-04
Siemens industrial products using the Discovery Service of the OPC UA protocol stack by the OPC foundation
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens industrial products using the Discovery Service of the OPC UA protocol stack by the OPC foundation
Last RevisedDecember 04, 2017
Alert CodeICSA-17-243-01
## CVSS v3 8.2
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Siemens
Equipment: Industrial products using the Discovery Service of the OPC UA protocol stack by the OPC foundation
Vulnerability: Improper Restriction of XML External Entity Reference
## AFFECTED PRODUCTS
Siemens reports that the vulnerability affects the following industrial products, which use the Discovery Service of the OPC UA
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/100559http://www.securitytracker.com/id/1039510https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2017-12069.pdfhttps://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-535640.pdfhttp://www.securityfocus.com/bid/100559http://www.securitytracker.com/id/1039510https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2017-12069.pdfhttps://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-535640.pdf
2017-08-30
Published