PatchSiren cyber security CVE debrief
CVE-2020-11656 Rockwell Automation CVE debrief
CVE-2020-11656 is a critical SQLite use-after-free issue cited by CISA for Rockwell Automation DataMosaix Private Cloud. The advisory states that affected versions are <=7.09 and that the issue is addressed in v7.11.01. Given the advisory’s 9.8 CVSS score and network-based attack model, organizations should prioritize remediation and ICS hardening.
- Vendor
- Rockwell Automation
- Product
- DataEdgePlatform DataMosaix Private Cloud
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-28
- Original CVE updated
- 2025-01-28
- Advisory published
- 2025-01-28
- Advisory updated
- 2025-01-28
Who should care
Organizations running Rockwell Automation DataEdgePlatform DataMosaix Private Cloud, especially environments that support industrial automation or other OT/ICS operations and teams responsible for patching or securing affected deployments.
Technical summary
The issue is described as a use-after-free vulnerability in SQLite’s ALTER TABLE implementation. CISA notes that it was demonstrated by an ORDER BY clause in a compound SELECT statement. In the supplied advisory metadata, the flaw is scored CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the affected product range is listed as Rockwell Automation DataEdgePlatform DataMosaix Private Cloud <=7.09.
Defensive priority
Immediate remediation priority for exposed or in-use systems.
Recommended defensive actions
- Upgrade Rockwell Automation DataEdgePlatform DataMosaix Private Cloud to v7.11.01 or later as recommended by the vendor.
- Confirm whether any deployed instances are at version 7.09 or earlier and schedule urgent remediation for all affected assets.
- Review the Rockwell Automation security advisory and apply the vendor’s suggested security best practices.
- Use CISA ICS recommended practices and defense-in-depth guidance to reduce exposure around industrial automation systems.
- If upgrades must be staged, limit access to affected systems and closely monitor for unexpected application or database faults.
Evidence notes
The supplied CISA CSAF advisory ICSA-25-028-05 was published and modified on 2025-01-28. It identifies Rockwell Automation DataEdgePlatform DataMosaix Private Cloud as affected at <=7.09 and states the issue is fixed in v7.11.01. The description attributes the flaw to SQLite’s ALTER TABLE implementation and says it was demonstrated with an ORDER BY clause in a compound SELECT statement. The supplied corpus does not include a KEV listing for this CVE.
Official resources
-
CVE-2020-11656 CVE record
CVE.org
-
CVE-2020-11656 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
Publicly disclosed in CISA advisory ICSA-25-028-05 on 2025-01-28; no KEV date or KEV due date is provided in the supplied data.