CVE-2020-27263
Published: Jan 13, 2021
Modified: Aug 4, 2024
Description
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.
| Vendor | Product | Versions |
|---|---|---|
n/a | PTC Kepware KEPServerEX | affected v6.0 to v6.9 |
n/a | ThingWorx Kepware Server | affected v6.8 and v6.9 |
n/a | ThingWorx Industrial Connectivity | affected All versions |
n/a | OPC-Aggregator | affected All versions |
n/a | Rockwell Automation KEPServer Enterprise | affected All versions |
n/a | GE Digital Industrial Gateway Server | affected v7.68.804affected v7.66 |
n/a | Software Toolbox TOP Server | affected All 6.x versions |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now