9.8
CVE-2019-16871
- EPSS 5.3%
- Veröffentlicht 19.12.2019 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:31:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.3% | 0.915 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2017-001.pdf
https://www.ic4.be/2019/12/18/beckhoff-cve-2019-16871/#more-648