CVE Vulnerabilities

CVE-2019-16871

Authentication Bypass by Spoofing

Published: Dec 19, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

NameVendorStart VersionEnd Version
TwincatBeckhoff3.0 (including)3.1 (excluding)
TwincatBeckhoff2.0 (including)2.0 (including)
TwincatBeckhoff3.1-build_4022 (including)3.1-build_4022 (including)
TwincatBeckhoff3.1-build_4024.0 (including)3.1-build_4024.0 (including)

References