CVE-2020-6970 Vulnerability Details

  /     /     /  

CVE-2020-6970 Metadata Quick Info

CVE Published: 19/02/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: icscert | Vendor: Emerson | Product: OpenEnterprise SCADA Server
Status : PUBLISHED

CVE-2020-6970 Description

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-122
CWE Name: HEAP-BASED BUFFER OVERFLOW CWE-122
Source: Emerson

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).