HIGH · 7.5

CVE-2020-27274

Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OP...

Vulnerability Description

Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HoneywellOpc Ua Tunneller< 6.3.0.8233

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-27274?

CVE-2020-27274 is a vulnerability with a CVSS score of 7.5 (HIGH). Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OP...

How severe is CVE-2020-27274?

CVE-2020-27274 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-27274?

Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Opc Ua Tunneller.