First published: Thu Nov 21 2019(Updated: )
When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Beckhoff TwinCAT Extended Automation Runtime | =3.1.4022.30 | |
Beckhoff TwinCAT Cx2030 | ||
Beckhoff TwinCAT Cx5140 | ||
Beckhoff TwinCAT Extended Automation Runtime | =3.1.4022.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5637 has a severity rating that indicates it can lead to a denial of service condition.
To fix CVE-2019-5637, update to Beckhoff TwinCAT versions later than 3.1.4022.30 or 3.1.4022.29.
CVE-2019-5637 affects Beckhoff TwinCAT 2 version 2304 and TwinCAT 3.1 versions prior to 4204.0.
CVE-2019-5637 is associated with a denial of service attack that occurs through malformed UDP packets.
CVE-2019-5637 is a remote vulnerability, as it requires sending a packet to the device over the network.