Vulnerability Details CVE-2020-6970
A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.025
EPSS Ranking 82.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-6970
-
cpe:2.3:a:emerson:openenterprise_scada_server:2.8.3
-
cpe:2.3:a:emerson:openenterprise_scada_server:3.1
-
cpe:2.3:a:emerson:openenterprise_scada_server:3.3.3