CVE-2020-27299

CRITICAL

OPC UA Tunneller <6.3.0.8233 - Info Disclosure

Title source: llm
STIX 2.1

Description

The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (versions prior to 6.3.0.8233).

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-021-03

Scores

CVSS v3 9.1
EPSS 0.0022
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
honeywell/opc_ua_tunneller < 6.3.0.8233
Published Jan 26, 2021
Tracked Since Feb 18, 2026