CVE-2020-27263: Ge Industrial Gateway Server
Critical severity, CVSS 9.1. EPSS: 5% chance of exploitation in the next 30 days.
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.
Affected products
- Ge Industrial Gateway Server: version 7.66 only; version 7.68.804 only
- PTC Kepware Kepserverex: version 6.0 only; version 6.9 only
- PTC Opc-Aggregator: affected versions not specified
- PTC Thingworx Industrial Connectivity: affected versions not specified
- PTC Thingworx Kepware Server: version 6.8 only; version 6.9 only
- Rockwellautomation Kepserver Enterprise: version 6.6.504.0 only; version 6.9.572.0 only
- Softwaretoolbox Top Server: from 6.0, up to and including 6.9
Published 2021-01-14. Last modified 2026-06-17.