Heap-Based Buffer Overflow in KEPServerEX and Related Products by Kepware Technologies
CVE-2020-27267

9.1CRITICAL

What is CVE-2020-27267?

Certain versions of KEPServerEX, ThingWorx Kepware Server, and other industrial connectivity products are exposed to a heap-based buffer overflow vulnerability. An attacker could exploit this flaw by sending a specially crafted OPC UA message, leading to a server crash and possible leakage of sensitive data. It is crucial for users of the affected products to implement appropriate security measures and apply relevant updates to mitigate this risk.

Affected Version(s)

GE Digital Industrial Gateway Server v7.68.804

GE Digital Industrial Gateway Server v7.66

OPC-Aggregator All versions

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.