PT-2020-6947 · Kepware+4 · Kepserverex+5

Published

2020-12-17

·

Updated

2021-01-21

·

CVE-2020-27267

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions KEPServerEX versions 6.0 through 6.9 ThingWorx Kepware Server versions 6.8 through 6.9 ThingWorx Industrial Connectivity (all versions) OPC-Aggregator (all versions) Rockwell Automation KEPServer Enterprise (affected versions not specified) GE Digital Industrial Gateway Server versions 7.66 through 7.68.804 Software Toolbox TOP Server versions 6.x
Description The issue is related to a heap-based buffer overflow that can be triggered by opening a specifically crafted OPC UA message. This could allow an attacker to crash the server and potentially leak data. The vulnerability can be exploited remotely, leading to a denial of service.
Recommendations For KEPServerEX versions 6.0 through 6.9, update to a version that includes a fix for the heap-based buffer overflow issue. For ThingWorx Kepware Server versions 6.8 and 6.9, update to a version that includes a fix for the heap-based buffer overflow issue. For ThingWorx Industrial Connectivity, restrict access to the OPC UA message handling functionality until a patch is available. For OPC-Aggregator, avoid processing specially crafted OPC UA messages until a fix is applied. For Rockwell Automation KEPServer Enterprise, contact the vendor for specific guidance on mitigating the issue. For GE Digital Industrial Gateway Server versions 7.66 through 7.68.804, update to a version that includes a fix for the heap-based buffer overflow issue. For Software Toolbox TOP Server versions 6.x, update to a version that includes a fix for the heap-based buffer overflow issue.

Fix

Memory Corruption

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-09020
CVE-2020-27267

Affected Products

Industrial Gateway Server
Enterprise Server
Kepserverex
Top Server
Thingworx Industrial Connectivity
Thingworx Kepware Server