← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-27263

KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
EPSS Probability:4.94%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-122 ↗HEAP-BASED BUFFER OVERFLOW CWE-122

Affected Products & Versions

Vendor Product Affected Versions
ge industrial_gateway_server 7.66, 7.68.804
ptc kepware_kepserverex 6.0, 6.9
ptc opc-aggregator all
ptc thingworx_industrial_connectivity all
ptc thingworx_kepware_server 6.8, 6.9
rockwellautomation kepserver_enterprise 6.6.504.0, 6.9.572.0
softwaretoolbox top_server all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.941%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA
Reserved2020-10-19T00:00:00
Published2021-01-13T23:30:08
Last Updated2024-08-04T16:11:36

LINK COPIED TO CLIPBOARD