PT-2020-19318 · Emerson · Openenterprise Scada Server+1

Roman Lozko

·

Published

2020-02-19

·

Updated

2020-02-28

·

CVE-2020-6970

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emerson OpenEnterprise SCADA Server version 2.83 Emerson OpenEnterprise versions 3.1 through 3.3.3
Description A Heap-based Buffer Overflow issue allows a specially crafted script to execute code on the OpenEnterprise Server. This issue is present when Modbus or ROC Interfaces have been installed and are in use.
Recommendations For Emerson OpenEnterprise SCADA Server version 2.83, update the system to prevent the exploitation of the Heap-based Buffer Overflow issue. For Emerson OpenEnterprise versions 3.1 through 3.3.3, update the system to prevent the exploitation of the Heap-based Buffer Overflow issue. As a temporary workaround, consider restricting access to the Modbus or ROC Interfaces until a patch is available.

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6970

Affected Products

Openenterprise
Openenterprise Scada Server