// For flags

CVE-2020-27267

 

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.

KEPServerEX versiones v6.0 hasta v6.9, ThingWorx Kepware Server versiones v6.8 y v6.9, ThingWorx Industrial Connectivity (todas las versiones), OPC-Aggregator (todas las versiones), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server versiones v7.68.804 y v7.66, y Software Toolbox TOP Server, todas las versiones 6.x, son vulnerables a un desbordamiento del búfer en la región heap de la memoria. Abrir un mensaje OPC UA específicamente diseñado podría permitir a un atacante bloquear el servidor y potencialmente filtrar datos

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-10-19 CVE Reserved
  • 2021-01-13 CVE Published
  • 2024-01-02 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-416: Use After Free
  • CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ge
Search vendor "Ge"
Industrial Gateway Server
Search vendor "Ge" for product "Industrial Gateway Server"
7.66
Search vendor "Ge" for product "Industrial Gateway Server" and version "7.66"
-
Affected
Ge
Search vendor "Ge"
Industrial Gateway Server
Search vendor "Ge" for product "Industrial Gateway Server"
7.68.804
Search vendor "Ge" for product "Industrial Gateway Server" and version "7.68.804"
-
Affected
Ptc
Search vendor "Ptc"
Kepware Kepserverex
Search vendor "Ptc" for product "Kepware Kepserverex"
6.0
Search vendor "Ptc" for product "Kepware Kepserverex" and version "6.0"
-
Affected
Ptc
Search vendor "Ptc"
Kepware Kepserverex
Search vendor "Ptc" for product "Kepware Kepserverex"
6.9
Search vendor "Ptc" for product "Kepware Kepserverex" and version "6.9"
-
Affected
Ptc
Search vendor "Ptc"
Opc-aggregator
Search vendor "Ptc" for product "Opc-aggregator"
--
Affected
Ptc
Search vendor "Ptc"
Thingworx Industrial Connectivity
Search vendor "Ptc" for product "Thingworx Industrial Connectivity"
--
Affected
Ptc
Search vendor "Ptc"
Thingworx Kepware Server
Search vendor "Ptc" for product "Thingworx Kepware Server"
6.8
Search vendor "Ptc" for product "Thingworx Kepware Server" and version "6.8"
-
Affected
Ptc
Search vendor "Ptc"
Thingworx Kepware Server
Search vendor "Ptc" for product "Thingworx Kepware Server"
6.9
Search vendor "Ptc" for product "Thingworx Kepware Server" and version "6.9"
-
Affected
Rockwellautomation
Search vendor "Rockwellautomation"
Kepserver Enterprise
Search vendor "Rockwellautomation" for product "Kepserver Enterprise"
6.6.504.0
Search vendor "Rockwellautomation" for product "Kepserver Enterprise" and version "6.6.504.0"
-
Affected
Rockwellautomation
Search vendor "Rockwellautomation"
Kepserver Enterprise
Search vendor "Rockwellautomation" for product "Kepserver Enterprise"
6.9.572.0
Search vendor "Rockwellautomation" for product "Kepserver Enterprise" and version "6.9.572.0"
-
Affected
Softwaretoolbox
Search vendor "Softwaretoolbox"
Top Server
Search vendor "Softwaretoolbox" for product "Top Server"
>= 6.0 <= 6.9
Search vendor "Softwaretoolbox" for product "Top Server" and version " >= 6.0 <= 6.9"
-
Affected