PatchSiren

PatchSiren cyber security CVE debrief

CVE-2020-11656 Rockwell Automation CVE debrief

CVE-2020-11656 is a critical SQLite use-after-free issue cited by CISA for Rockwell Automation DataMosaix Private Cloud. The advisory states that affected versions are <=7.09 and that the issue is addressed in v7.11.01. Given the advisory’s 9.8 CVSS score and network-based attack model, organizations should prioritize remediation and ICS hardening.

Vendor
Rockwell Automation
Product
DataEdgePlatform DataMosaix Private Cloud
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-01-28
Original CVE updated
2025-01-28
Advisory published
2025-01-28
Advisory updated
2025-01-28

Who should care

Organizations running Rockwell Automation DataEdgePlatform DataMosaix Private Cloud, especially environments that support industrial automation or other OT/ICS operations and teams responsible for patching or securing affected deployments.

Technical summary

The issue is described as a use-after-free vulnerability in SQLite’s ALTER TABLE implementation. CISA notes that it was demonstrated by an ORDER BY clause in a compound SELECT statement. In the supplied advisory metadata, the flaw is scored CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the affected product range is listed as Rockwell Automation DataEdgePlatform DataMosaix Private Cloud <=7.09.

Defensive priority

Immediate remediation priority for exposed or in-use systems.

Recommended defensive actions

  • Upgrade Rockwell Automation DataEdgePlatform DataMosaix Private Cloud to v7.11.01 or later as recommended by the vendor.
  • Confirm whether any deployed instances are at version 7.09 or earlier and schedule urgent remediation for all affected assets.
  • Review the Rockwell Automation security advisory and apply the vendor’s suggested security best practices.
  • Use CISA ICS recommended practices and defense-in-depth guidance to reduce exposure around industrial automation systems.
  • If upgrades must be staged, limit access to affected systems and closely monitor for unexpected application or database faults.

Evidence notes

The supplied CISA CSAF advisory ICSA-25-028-05 was published and modified on 2025-01-28. It identifies Rockwell Automation DataEdgePlatform DataMosaix Private Cloud as affected at <=7.09 and states the issue is fixed in v7.11.01. The description attributes the flaw to SQLite’s ALTER TABLE implementation and says it was demonstrated with an ORDER BY clause in a compound SELECT statement. The supplied corpus does not include a KEV listing for this CVE.

Sources and references

Verified primary and authoritative sources

  • CVE-2020-11656 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2020-11656

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2020-11656 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2020-11656

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-028-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-028-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.