CVE-2020-27297: Buffer Overflow
Published Jan 26, 2021
·Updated
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Affected Software
2 affected componentsFixes available
Matrikon, a subsidiary of Honeywell OPC UA Tunneller<6.3.0.8233
6.3.0.8233
Honeywell Opc Ua Tunneller<6.3.0.8233
Event History
Jan 26, 2021
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-27297.
2
What is the severity of CVE-2020-27297?
The severity of CVE-2020-27297 is critical with a score of 9.8.
3
Which product is affected by CVE-2020-27297?
The Honeywell OPC UA Tunneller (versions prior to 6.3.0.8233) is affected by CVE-2020-27297.
4
What is the impact of CVE-2020-27297?
CVE-2020-27297 allows an attacker to manipulate memory with controlled values and remotely execute code on the affected product.
5
Is there a fix available for CVE-2020-27297?
Yes, updating the OPC UA Tunneller to version 6.3.0.8233 or later will fix CVE-2020-27297.