PatchSiren

PatchSiren cyber security CVE debrief

CVE-2020-11656 Rockwell Automation CVE debrief

CVE-2020-11656 is a critical SQLite use-after-free issue cited by CISA for Rockwell Automation DataMosaix Private Cloud. The advisory states that affected versions are <=7.09 and that the issue is addressed in v7.11.01. Given the advisory’s 9.8 CVSS score and network-based attack model, organizations should prioritize remediation and ICS hardening.

Vendor
Rockwell Automation
Product
DataEdgePlatform DataMosaix Private Cloud
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-01-28
Original CVE updated
2025-01-28
Advisory published
2025-01-28
Advisory updated
2025-01-28

Who should care

Organizations running Rockwell Automation DataEdgePlatform DataMosaix Private Cloud, especially environments that support industrial automation or other OT/ICS operations and teams responsible for patching or securing affected deployments.

Technical summary

The issue is described as a use-after-free vulnerability in SQLite’s ALTER TABLE implementation. CISA notes that it was demonstrated by an ORDER BY clause in a compound SELECT statement. In the supplied advisory metadata, the flaw is scored CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the affected product range is listed as Rockwell Automation DataEdgePlatform DataMosaix Private Cloud <=7.09.

Defensive priority

Immediate remediation priority for exposed or in-use systems.

Recommended defensive actions

  • Upgrade Rockwell Automation DataEdgePlatform DataMosaix Private Cloud to v7.11.01 or later as recommended by the vendor.
  • Confirm whether any deployed instances are at version 7.09 or earlier and schedule urgent remediation for all affected assets.
  • Review the Rockwell Automation security advisory and apply the vendor’s suggested security best practices.
  • Use CISA ICS recommended practices and defense-in-depth guidance to reduce exposure around industrial automation systems.
  • If upgrades must be staged, limit access to affected systems and closely monitor for unexpected application or database faults.

Evidence notes

The supplied CISA CSAF advisory ICSA-25-028-05 was published and modified on 2025-01-28. It identifies Rockwell Automation DataEdgePlatform DataMosaix Private Cloud as affected at <=7.09 and states the issue is fixed in v7.11.01. The description attributes the flaw to SQLite’s ALTER TABLE implementation and says it was demonstrated with an ORDER BY clause in a compound SELECT statement. The supplied corpus does not include a KEV listing for this CVE.

Official resources

Publicly disclosed in CISA advisory ICSA-25-028-05 on 2025-01-28; no KEV date or KEV due date is provided in the supplied data.