PatchSiren cyber security CVE debrief
CVE-2020-11656 Rockwell Automation CVE debrief
CVE-2020-11656 is a critical SQLite use-after-free issue cited by CISA for Rockwell Automation DataMosaix Private Cloud. The advisory states that affected versions are <=7.09 and that the issue is addressed in v7.11.01. Given the advisory’s 9.8 CVSS score and network-based attack model, organizations should prioritize remediation and ICS hardening.
- Vendor
- Rockwell Automation
- Product
- DataEdgePlatform DataMosaix Private Cloud
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-28
- Original CVE updated
- 2025-01-28
- Advisory published
- 2025-01-28
- Advisory updated
- 2025-01-28
Who should care
Organizations running Rockwell Automation DataEdgePlatform DataMosaix Private Cloud, especially environments that support industrial automation or other OT/ICS operations and teams responsible for patching or securing affected deployments.
Technical summary
The issue is described as a use-after-free vulnerability in SQLite’s ALTER TABLE implementation. CISA notes that it was demonstrated by an ORDER BY clause in a compound SELECT statement. In the supplied advisory metadata, the flaw is scored CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the affected product range is listed as Rockwell Automation DataEdgePlatform DataMosaix Private Cloud <=7.09.
Defensive priority
Immediate remediation priority for exposed or in-use systems.
Recommended defensive actions
- Upgrade Rockwell Automation DataEdgePlatform DataMosaix Private Cloud to v7.11.01 or later as recommended by the vendor.
- Confirm whether any deployed instances are at version 7.09 or earlier and schedule urgent remediation for all affected assets.
- Review the Rockwell Automation security advisory and apply the vendor’s suggested security best practices.
- Use CISA ICS recommended practices and defense-in-depth guidance to reduce exposure around industrial automation systems.
- If upgrades must be staged, limit access to affected systems and closely monitor for unexpected application or database faults.
Evidence notes
The supplied CISA CSAF advisory ICSA-25-028-05 was published and modified on 2025-01-28. It identifies Rockwell Automation DataEdgePlatform DataMosaix Private Cloud as affected at <=7.09 and states the issue is fixed in v7.11.01. The description attributes the flaw to SQLite’s ALTER TABLE implementation and says it was demonstrated with an ORDER BY clause in a compound SELECT statement. The supplied corpus does not include a KEV listing for this CVE.
Sources and references
Verified primary and authoritative sources
-
CVE-2020-11656 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2020-11656
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2020-11656 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-11656
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-028-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-028-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.