CVE-2020-6970
A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-787
- Affected
- emerson/openenterprise scada server
- Source
- ics-cert@hq.dhs.gov
References
- https://www.us-cert.gov/ics/advisories/icsa-20-049-02Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-20-049-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.