CVE-2020-6970

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-20-049-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emerson:openenterprise_scada_server:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:openenterprise_scada_server:2.8.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-02-19 21:15

Updated : 2024-02-04 20:39


NVD link : CVE-2020-6970

Mitre link : CVE-2020-6970

CVE.ORG link : CVE-2020-6970


JSON object : View

Products Affected

emerson

  • openenterprise_scada_server
CWE
CWE-787

Out-of-bounds Write

CWE-122

Heap-based Buffer Overflow