Vulnerability Details CVE-2017-12069
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.9%
CVSS Severity
CVSS v3 Score 8.2
CVSS v2 Score 6.4
Products affected by CVE-2017-12069
-
cpe:2.3:a:ocpfoundation:local_discovery_server:1.01.333.0
-
cpe:2.3:a:ocpfoundation:ua_.net:2017-03-21
-
cpe:2.3:a:siemens:simatic_pcs7:7.1
-
cpe:2.3:a:siemens:simatic_pcs7:8.0
-
cpe:2.3:a:siemens:simatic_pcs7:8.1
-
cpe:2.3:a:siemens:wincc:5.0
-
cpe:2.3:a:siemens:wincc:6.0
-
cpe:2.3:a:siemens:wincc:7.0
-
cpe:2.3:a:siemens:wincc:7.1
-
cpe:2.3:a:siemens:wincc:7.2
-
cpe:2.3:a:siemens:wincc:7.3
-
cpe:2.3:a:siemens:wincc:7.4