Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Twincat | Beckhoff | 3.0 (including) | 3.1 (excluding) |
Twincat | Beckhoff | 2.0 (including) | 2.0 (including) |
Twincat | Beckhoff | 3.1-build_4022 (including) | 3.1-build_4022 (including) |
Twincat | Beckhoff | 3.1-build_4024.0 (including) | 3.1-build_4024.0 (including) |