Vulnerability record · CVE-2017-12069 · published 30 August 2017
CVE-2017-12069: Siemens simatic pcs7 xml external entity (xxe) vulnerability
Siemens · Simatic Pcs7
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
Description
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100559 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039510 | |
| https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2017-12069.pdf | PatchVendor Advisory |
| https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-535640.pdf | Vendor Advisory |
| http://www.securityfocus.com/bid/100559 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039510 | |
| https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2017-12069.pdf | PatchVendor Advisory |
| https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-535640.pdf | Vendor Advisory |
Track CVE-2017-12069 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12069), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.