CVE-2020-27267
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.
KEPServerEX versiones v6.0 hasta v6.9, ThingWorx Kepware Server versiones v6.8 y v6.9, ThingWorx Industrial Connectivity (todas las versiones), OPC-Aggregator (todas las versiones), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server versiones v7.68.804 y v7.66, y Software Toolbox TOP Server, todas las versiones 6.x, son vulnerables a un desbordamiento del búfer en la región heap de la memoria. Abrir un mensaje OPC UA específicamente diseñado podría permitir a un atacante bloquear el servidor y potencialmente filtrar datos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-19 CVE Reserved
- 2021-01-13 CVE Published
- 2024-01-02 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-352-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ge Search vendor "Ge" | Industrial Gateway Server Search vendor "Ge" for product "Industrial Gateway Server" | 7.66 Search vendor "Ge" for product "Industrial Gateway Server" and version "7.66" | - |
Affected
| ||||||
Ge Search vendor "Ge" | Industrial Gateway Server Search vendor "Ge" for product "Industrial Gateway Server" | 7.68.804 Search vendor "Ge" for product "Industrial Gateway Server" and version "7.68.804" | - |
Affected
| ||||||
Ptc Search vendor "Ptc" | Kepware Kepserverex Search vendor "Ptc" for product "Kepware Kepserverex" | 6.0 Search vendor "Ptc" for product "Kepware Kepserverex" and version "6.0" | - |
Affected
| ||||||
Ptc Search vendor "Ptc" | Kepware Kepserverex Search vendor "Ptc" for product "Kepware Kepserverex" | 6.9 Search vendor "Ptc" for product "Kepware Kepserverex" and version "6.9" | - |
Affected
| ||||||
Ptc Search vendor "Ptc" | Opc-aggregator Search vendor "Ptc" for product "Opc-aggregator" | - | - |
Affected
| ||||||
Ptc Search vendor "Ptc" | Thingworx Industrial Connectivity Search vendor "Ptc" for product "Thingworx Industrial Connectivity" | - | - |
Affected
| ||||||
Ptc Search vendor "Ptc" | Thingworx Kepware Server Search vendor "Ptc" for product "Thingworx Kepware Server" | 6.8 Search vendor "Ptc" for product "Thingworx Kepware Server" and version "6.8" | - |
Affected
| ||||||
Ptc Search vendor "Ptc" | Thingworx Kepware Server Search vendor "Ptc" for product "Thingworx Kepware Server" | 6.9 Search vendor "Ptc" for product "Thingworx Kepware Server" and version "6.9" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Kepserver Enterprise Search vendor "Rockwellautomation" for product "Kepserver Enterprise" | 6.6.504.0 Search vendor "Rockwellautomation" for product "Kepserver Enterprise" and version "6.6.504.0" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Kepserver Enterprise Search vendor "Rockwellautomation" for product "Kepserver Enterprise" | 6.9.572.0 Search vendor "Rockwellautomation" for product "Kepserver Enterprise" and version "6.9.572.0" | - |
Affected
| ||||||
Softwaretoolbox Search vendor "Softwaretoolbox" | Top Server Search vendor "Softwaretoolbox" for product "Top Server" | >= 6.0 <= 6.9 Search vendor "Softwaretoolbox" for product "Top Server" and version " >= 6.0 <= 6.9" | - |
Affected
|