CVE-2020-27267: Ge Industrial Gateway Server
Critical severity, CVSS 9.1. EPSS: 5% chance of exploitation in the next 30 days.
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.
Affected products
- Ge Industrial Gateway Server: version 7.66 only; version 7.68.804 only
- PTC Kepware Kepserverex: version 6.0 only; version 6.9 only
- PTC Opc-Aggregator: affected versions not specified
- PTC Thingworx Industrial Connectivity: affected versions not specified
- PTC Thingworx Kepware Server: version 6.8 only; version 6.9 only
- Rockwellautomation Kepserver Enterprise: version 6.6.504.0 only; version 6.9.572.0 only
- Softwaretoolbox Top Server: from 6.0, up to and including 6.9
Published 2021-01-14. Last modified 2026-06-17.