Vulnerability in Beckhoff TwinCAT Automation Software
CVE-2017-16726

9.1CRITICAL

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
27 June 2018

What is CVE-2017-16726?

The TwinCAT system from Beckhoff is susceptible to security vulnerabilities due to its use of the ADS protocol, which lacks encryption mechanisms. This allows attackers to observe legitimate ADS traffic and forge arbitrary ADS packets, potentially leading to unauthorized control or disruption of automation processes in industrial environments. Organizations using TwinCAT should adopt comprehensive security practices to mitigate risks associated with this vulnerability.

Affected Version(s)

Beckhoff TwinCAT Version 2, Version 3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.