Vulnerability Description
Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Opc Ua Tunneller | < 6.3.0.8233 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03Third Party AdvisoryUS Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-27274?
CVE-2020-27274 is a vulnerability with a CVSS score of 7.5 (HIGH). Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OP...
How severe is CVE-2020-27274?
CVE-2020-27274 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27274?
Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Opc Ua Tunneller.