CVE-2018-12585: XEE
Published Sep 14, 2018
·Updated
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
Affected Software
2 affected components
opcfoundation Ua-.net-legacy<=1.03.342
opcfoundation Ua-java<=1.3.343
Event History
Sep 14, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-12585?
CVE-2018-12585 is an XXE vulnerability in the OPC UA Java and .NET Legacy Stack.
2
How does CVE-2018-12585 impact my system?
CVE-2018-12585 can allow remote attackers to trigger a denial of service.
3
What software versions are affected by CVE-2018-12585?
Versions up to 1.03.342 of OPC UA .NET Legacy Stack and versions up to 1.3.343 of OPC UA Java are affected by CVE-2018-12585.
4
What is the severity of CVE-2018-12585?
CVE-2018-12585 has a severity rating of 8.2 (high).
5
How can I fix CVE-2018-12585?
There is currently no official fix or patch available for CVE-2018-12585. It is recommended to follow the security recommendations provided by the OPC Foundation.