Out-of-Bounds Read Vulnerability in OPC UA Tunneller by CODESYS
CVE-2020-27299

9.1CRITICAL

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
26 January 2021

What is CVE-2020-27299?

The OPC UA Tunneller by CODESYS is susceptible to an out-of-bounds read vulnerability that can potentially allow an attacker to access sensitive data or disrupt service functionality. This flaw particularly affects versions before 6.3.0.8233, where improper handling of memory boundaries may lead to information leakage or system crashes. It is crucial for users to apply available patches to safeguard their systems from exploitation.

Affected Version(s)

OPC UA Tunneller All versions prior to 6.3.0.8233

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.