PT-2020-19318 · Emerson · Openenterprise Scada Server+1
Roman Lozko
·
Published
2020-02-19
·
Updated
2020-02-28
·
CVE-2020-6970
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Emerson OpenEnterprise SCADA Server version 2.83
Emerson OpenEnterprise versions 3.1 through 3.3.3
Description
A Heap-based Buffer Overflow issue allows a specially crafted script to execute code on the OpenEnterprise Server. This issue is present when Modbus or ROC Interfaces have been installed and are in use.
Recommendations
For Emerson OpenEnterprise SCADA Server version 2.83, update the system to prevent the exploitation of the Heap-based Buffer Overflow issue.
For Emerson OpenEnterprise versions 3.1 through 3.3.3, update the system to prevent the exploitation of the Heap-based Buffer Overflow issue.
As a temporary workaround, consider restricting access to the Modbus or ROC Interfaces until a patch is available.
Fix
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openenterprise
Openenterprise Scada Server