High severity8.2OSV Advisory· Published Sep 14, 2018· Updated Jun 17, 2026
CVE-2018-12585
CVE-2018-12585
Description
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
Affected products
3cpe:2.3:a:opcfoundation:ua-.net-legacy:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:opcfoundation:ua-.net-legacy:*:*:*:*:*:*:*:*range: <=1.03.342
- (no CPE)range: 1.02.336, 1.03.340, 1.03.341, …
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/105538nvdThird Party AdvisoryVDB Entry
- opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2018-12585.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.