Description
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-19780 | KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data. |
References
| Link | Providers |
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-20-352-02 |
|
History
No history.
Subscriptions
Ge
Subscribe
Industrial Gateway Server
Subscribe
Ptc
Subscribe
Kepware Kepserverex
Subscribe
Opc-aggregator
Subscribe
Thingworx Industrial Connectivity
Subscribe
Thingworx Kepware Server
Subscribe
Rockwellautomation
Subscribe
Kepserver Enterprise
Subscribe
Softwaretoolbox
Subscribe
Top Server
Subscribe
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T16:11:36.412Z
Reserved: 2020-10-19T00:00:00.000Z
Link: CVE-2020-27267
No data.
Status : Modified
Published: 2021-01-14T00:15:13.510
Modified: 2024-11-21T05:20:58.280
Link: CVE-2020-27267
No data.
OpenCVE Enrichment
No data.
EUVD