What the vulnerability does

01Description

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.

Key dates

02Disclosure timeline

February 19, 2020 CVE published
August 4, 2024 Record updated