CVE-2020-27274: Honeywell Opc Ua Tunneller

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).

Affected products

  • Honeywell Opc Ua Tunneller: before 6.3.0.8233 (fixed in 6.3.0.8233)

Published 2021-01-26. Last modified 2026-06-17.