IM
IronMonkey Threat Research

CVE-2020-27299 CRITICAL

Published: 2021-01-26 | Last Modified: 2024-11-21 | Status: Modified

Description

The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (versions prior to 6.3.0.8233).

Additional Descriptions (1)

El producto afectado es vulnerable a una lectura fuera de límites, lo que puede permitir a un atacante obtener y divulgar información confidencial o causar el bloqueo del dispositivo en el OPC UA Tunneller (versiones anteriores a 6.3.0.8233)

CVSS Metrics

Base Score: 9.1 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 5.2

Base Score: 6.4 (MEDIUM)

AV:N/AC:L/Au:N/C:P/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 4.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-125
[email protected] Primary
en CWE-125

Affected Products

Vendor Product Version Update Type
honeywell opc_ua_tunneller * <built-in method update of dict object at 0x7c3bf397af00> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:honeywell:opc_ua_tunneller:*:*:*:*:*:*:*:*

References

Notification
Message here