Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. OPCFoundation.NetStandard.Opc.Ua
  4. ›
  5. CVE-2018-12585

CVE-2018-12585: Improper Restriction of XML External Entity Reference

September 14, 2018 (updated November 27, 2018)

An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.

References

  • www.securityfocus.com/bid/105538
  • nvd.nist.gov/vuln/detail/CVE-2018-12585
  • opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2018-12585.pdf

Code Behaviors & Features

Detect and mitigate CVE-2018-12585 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.03.342

Fixed versions

  • 1.3.348

Solution

Upgrade to version 1.3.348 or above.

Impact 8.2 HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-611: Improper Restriction of XML External Entity Reference

Source file

nuget/OPCFoundation.NetStandard.Opc.Ua/CVE-2018-12585.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:10 +0000.