Vulnerability Details CVE-2020-6970
A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-6970
-
cpe:2.3:a:emerson:openenterprise_scada_server:2.8.3
-
cpe:2.3:a:emerson:openenterprise_scada_server:3.1
-
cpe:2.3:a:emerson:openenterprise_scada_server:3.3.3