CVE-2017-12070: Input Validation
Published Jun 14, 2018
·Updated
Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.
Affected Software
1 affected component
opcfoundation Ua-.net-legacy=1.02.336.0
Event History
Jun 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is CVE-2017-12070?
CVE-2017-12070 is a vulnerability where unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.
2
What is the severity of CVE-2017-12070?
CVE-2017-12070 has a severity rating of 8.8 (high).
3
Which software versions are affected by CVE-2017-12070?
CVE-2017-12070 affects the following software version: UA-.NET-Legacy 1.02.336.0
4
How can I fix CVE-2017-12070?
To fix CVE-2017-12070, ensure that you are using signed versions of the DLLs from the OPC Foundation and apply any available patches or updates.
5
Where can I find more information about CVE-2017-12070?
You can find more information about CVE-2017-12070 in the OPC Foundation Security Bulletin available at this link: https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2017-12070.pdf