First published: Tue Jan 26 2021(Updated: )
The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Opc Ua Tunneller | <6.3.0.8233 | |
Matrikon, a subsidiary of Honeywell OPC UA Tunneller | <6.3.0.8233 | 6.3.0.8233 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27299 is a vulnerability in the OPC UA Tunneller that allows an attacker to obtain sensitive data or crash the device.
The severity of CVE-2020-27299 is critical with a CVSS score of 9.1.
The OPC UA Tunneller versions prior to 6.3.0.8233 are affected by CVE-2020-27299.
An attacker can obtain and disclose sensitive data or cause the device to crash with CVE-2020-27299.
To mitigate CVE-2020-27299, update the OPC UA Tunneller to version 6.3.0.8233 or newer.