Description
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-7902 | Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added. |
References
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-16T17:28:00.754Z
Reserved: 2017-11-09T00:00:00.000Z
Link: CVE-2017-16718
No data.
Status : Modified
Published: 2018-06-27T19:29:00.233
Modified: 2024-11-21T03:16:50.853
Link: CVE-2017-16718
No data.
OpenCVE Enrichment
No data.
EUVD