CVE Vulnerabilities

CVE-2019-16871

Authentication Bypass by Spoofing

Published: Dec 19, 2019 | Modified: Jul 21, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Twincat Beckhoff 3.0 (including) 3.1 (excluding)
Twincat Beckhoff 2.0 (including) 2.0 (including)
Twincat Beckhoff 3.1-build_4022 (including) 3.1-build_4022 (including)
Twincat Beckhoff 3.1-build_4024.0 (including) 3.1-build_4024.0 (including)

References