Lucene search

K
nvd[email protected]NVD:CVE-2020-12526
HistoryMay 13, 2021 - 2:15 p.m.

CVE-2020-12526

2021-05-1314:15:17
CWE-20
web.nvd.nist.gov
3
twincat
opc ua
ipc diagnostics
beckhoff automation
denial of service

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

42.6%

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.

Affected configurations

Nvd
Node
beckhoffipc_diagnostics_ua_serverRange3.1.0.1
OR
beckhofftf6100Range3.3.18
OR
beckhofftwincat_opc_ua_serverRange2.3.0.12
VendorProductVersionCPE
beckhoffipc_diagnostics_ua_server*cpe:2.3:a:beckhoff:ipc_diagnostics_ua_server:*:*:*:*:*:*:*:*
beckhofftf6100*cpe:2.3:a:beckhoff:tf6100:*:*:*:*:*:*:*:*
beckhofftwincat_opc_ua_server*cpe:2.3:a:beckhoff:twincat_opc_ua_server:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

42.6%

Related for NVD:CVE-2020-12526