← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-27265

KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a stack-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and remotely execute code.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:10.06%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-121 ↗STACK-BASED BUFFER OVERFLOW CWE-121

Affected Products & Versions

Vendor Product Affected Versions
ge industrial_gateway_server 7.66, 7.68.804
ptc kepware_kepserverex 6.0, 6.9
ptc opc-aggregator all
ptc thingworx_industrial_connectivity all
ptc thingworx_kepware_server 6.8, 6.9
rockwellautomation kepserver_enterprise 6.6.504.0, 6.9.572.0
softwaretoolbox top_server all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
10.062%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA
Reserved2020-10-19T00:00:00
Published2021-01-13T23:33:45
Last Updated2024-08-04T16:11:36

LINK COPIED TO CLIPBOARD