CVE-2020-27274
Last modified
CVE-2020-27274 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Opc Ua Tunneller | < 6.3.0.8233 |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27274?
How severe is CVE-2020-27274?
How do I fix CVE-2020-27274?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27267KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and …9.1
- CVE-2020-27268In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and A…6.5
- CVE-2020-27269In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and A…5.7
- CVE-2020-2727Vulnerability in the Oracle VM VirtualBox product of Oracle …6
- CVE-2020-27270SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, …5.7
- CVE-2020-27272SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, …5.7
- CVE-2020-27275Delta Electronics DOPSoft Version 4.0.8.21 and prior is vuln…7.8
- CVE-2020-27276SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A,…5.7
- CVE-2020-27277Delta Electronics DOPSoft Version 4.0.8.21 and prior has a n…7.8
- CVE-2020-27278In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and pri…5.2
- CVE-2020-27279A NULL pointer deference vulnerability has been identified i…7.5
- CVE-2020-2728Vulnerability in the Identity Manager product of Oracle Fusi…7.5
Are you affected by CVE-2020-27274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
