CVE-2020-6970

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-20-049-02 Third Party Advisory US Government Resource
https://www.us-cert.gov/ics/advisories/icsa-20-049-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emerson:openenterprise_scada_server:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:openenterprise_scada_server:2.8.3:*:*:*:*:*:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
References () https://www.us-cert.gov/ics/advisories/icsa-20-049-02 - Third Party Advisory, US Government Resource () https://www.us-cert.gov/ics/advisories/icsa-20-049-02 - Third Party Advisory, US Government Resource

Information

Published : 2020-02-19 21:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-6970

Mitre link : CVE-2020-6970

CVE.ORG link : CVE-2020-6970


JSON object : View

Products Affected

emerson

  • openenterprise_scada_server
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write