Vulnerability Description
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opcfoundation | Unified Architecture-.Net-Legacy | <= 1.03.342 |
| Opcfoundation | Unified Architecture-Java | <= 1.03.343 |
| Opcfoundation | Unified Architecture .Net-Standard | <= 1.03.352.12 |
| Opcfoundation | Unified Architecture Ansic | <= 1.03.340 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.html
- http://www.securityfocus.com/bid/105538Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041909Third Party AdvisoryVDB Entry
- https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_FoundatioVendor Advisory
- https://www.debian.org/security/2018/dsa-4359Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.html
- http://www.securityfocus.com/bid/105538Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041909Third Party AdvisoryVDB Entry
- https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_FoundatioVendor Advisory
- https://www.debian.org/security/2018/dsa-4359Third Party Advisory
FAQ
What is CVE-2018-12086?
CVE-2018-12086 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
How severe is CVE-2018-12086?
CVE-2018-12086 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12086?
Check the references section above for vendor advisories and patch information. Affected products include: Opcfoundation Unified Architecture-.Net-Legacy, Opcfoundation Unified Architecture-Java, Opcfoundation Unified Architecture .Net-Standard, Opcfoundation Unified Architecture Ansic, Debian Debian Linux.