← Back

CVE-2020-12494

nvd nist
Published: Jun 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD (Secondary)

Description

Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device.

Affected (6)

2 products
Twincat Driver
Twincat
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.1.0.3603
Running on/withPlatform Versions
Intel
82547ei
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.1.0.3512
Running on/withPlatform Versions
Beckhoff
Twincat
Version 3.1 build_4022
Configuration C
1 vulnerable · 14 platform
Vulnerable SoftwareAffected Versions
Up to 2.11.0.2120
Running on/withPlatform Versions
Intel
82540em
All versions
Intel
82540ep
All versions
Intel
82541ei
All versions
Intel
82541er
All versions
Intel
82541gi
All versions
Intel
82541pi
All versions
Intel
82544ei
All versions
Intel
82544gc
All versions
Intel
82545em
All versions
Intel
82545gm
All versions
Intel
82546eb
All versions
Intel
82546gb
All versions
Intel
82547ei
All versions
Intel
82547gi
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.1.0.3600
Running on/withPlatform Versions
Beckhoff
Twincat
Version 3.1 build_402
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.1.0.3500
Running on/withPlatform Versions
Beckhoff
Twincat
Version 3.1 build_4024
Configuration F
1 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Up to 2.11.0.2117
Running on/withPlatform Versions
Beckhoff
Twincat
Version 2.11 build_2350
Intel
82557
All versions
Intel
82558
All versions
Intel
82559
All versions

References (2)

Source: info@cert.vde.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.