Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) in OPC UA applications of SAP Plant Connectivity, SAP security note 2674215

SAP Note 2674215

SAP security note 2674215, "Denial of service (DOS) in OPC UA applications of SAP Plant Connectivity". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

This SAP Security Note addresses two critical vulnerabilities in SAP Plant Connectivity OPC UA applications that could lead to Denial of Service (DoS):

  • CVE-2018-12585: an XML External Entity (XXE) vulnerability allows attackers to crash or flood the OPC UA server, preventing legitimate users from accessing services.
  • CVE-2018-12086: a stack overflow vulnerability enables attackers to disrupt services by causing the OPC UA server to crash.

Solution

Apply the respective patch based on your SAP Plant Connectivity version.

  • Backup: execute a data backup before starting the installation.
  • Stop Services: ensure all agent instances are stopped and the Management Console is closed.
  • Install Patch: download the appropriate installation program from the SAP Service Marketplace and follow the instructions in the installation guide.
  • Restart System: if the installation program requests a system restart, perform it before continuing.

CVSS

Score 8.2/10

Score 7.5/10

References

  • NIST NVD

Affected components

  • SAP Plant Connectivity (15.0, 15.1, 15.2)

Full note on SAP: SAP Support Launchpad note 2674215

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More