First published: Tue Oct 08 2019(Updated: )
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Beckhoff TwinCAT Extended Automation Runtime | =2.0-build2304 | |
Beckhoff TwinCAT Extended Automation Runtime | =3.1-build4024.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5636 has a medium severity level associated with it, indicating it poses a risk of denial of service.
To fix CVE-2019-5636, you should update to TwinCAT 2 version 2304 or TwinCAT 3.1 version 4204.1 or later.
CVE-2019-5636 causes the ADS Discovery Service to shut down when a malformed UDP packet is received, but other TwinCAT functions continue to operate normally.
CVE-2019-5636 affects TwinCAT 2 version 2304 and all prior versions, as well as TwinCAT 3.1 version 4204.0 and all prior versions.
There is no specific workaround for CVE-2019-5636, but updating to the patched versions is recommended to mitigate the vulnerability.