Information disclosure in TwinCAT - CVE-2020-12494

 

Information disclosure in TwinCAT - CVE-2020-12494

Published: July 6, 2020


Vulnerability identifier: #VU29534
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12494
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to TwinCAT RT network driver for Intel 8254x and 8255x does not properly construct frames if their payload is less than the minimum Ethernet frame size. As a result, arbitrary system memory contents is transmitted within in the padding bytes of the frame.


Affected software

TwinCAT

How to mitigate CVE-2020-12494

Contact your vendor to obtain patches.


External References

Related Security Bulletins