CVE-2020-6970

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-20-049-02 Third Party Advisory US Government Resource
https://www.us-cert.gov/ics/advisories/icsa-20-049-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emerson:openenterprise_scada_server:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:openenterprise_scada_server:2.8.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-02-19 21:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-6970

Mitre link : CVE-2020-6970

CVE.ORG link : CVE-2020-6970


JSON object : View

Products Affected

emerson

  • openenterprise_scada_server
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write