CVE-2020-6970
Summary
| CVE | CVE-2020-6970 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-19 21:15:00 UTC |
| Updated | 2020-02-28 18:54:00 UTC |
| Description | A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emerson | Openenterprise Scada Server | 2.8.3 | All | All | All |
| Application | Emerson | Openenterprise Scada Server | 2.8.3 | All | All | All |
| Application | Emerson | Openenterprise Scada Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Emerson OpenEnterprise | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.