CVE-2020-6970

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
19/02/2020
Last modified:
28/02/2020

Description

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emerson:openenterprise_scada_server:*:*:*:*:*:*:*:* 3.1 (including) 3.3.3 (including)
cpe:2.3:a:emerson:openenterprise_scada_server:2.8.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools