Heap-Based Buffer Overflow in KEPServerEX and Related Products by Kepware Technologies
CVE-2020-27267
9.1CRITICAL
What is CVE-2020-27267?
Certain versions of KEPServerEX, ThingWorx Kepware Server, and other industrial connectivity products are exposed to a heap-based buffer overflow vulnerability. An attacker could exploit this flaw by sending a specially crafted OPC UA message, leading to a server crash and possible leakage of sensitive data. It is crucial for users of the affected products to implement appropriate security measures and apply relevant updates to mitigate this risk.
Affected Version(s)
GE Digital Industrial Gateway Server v7.68.804
GE Digital Industrial Gateway Server v7.66
OPC-Aggregator All versions