Ics-Cert Beckhoff Twincat vulnerabilities
2 known vulnerabilities affecting ics-cert/beckhoff_twincat.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2017-16726P3CRITICALCVSS 9.1vVersion 2, Version 32018-06-27
CVE-2017-16726 [CRITICAL] CWE-285 CVE-2017-16726: Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in pro
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on performance and throughput. An attacker can forge arbitrary ADS packets when leg
nvd
CVE-2017-16718P4MEDIUMCVSS 5.9vVersion 32018-06-27
CVE-2017-16718 [MEDIUM] CWE-522 CVE-2017-16718: Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in p
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attack
nvd