5.3

CVE-2020-12494

Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BeckhoffTwincat Driver Version <= 3.1.0.3603
   BeckhoffTwincat Version3.1 Updatebuild_4024
   Intel82540em Version-
   Intel82540ep Version-
   Intel82541ei Version-
   Intel82541er Version-
   Intel82541gi Version-
   Intel82541pi Version-
   Intel82544ei Version-
   Intel82544gc Version-
   Intel82545em Version-
   Intel82545gm Version-
   Intel82546eb Version-
   Intel82546gb Version-
   Intel82547ei Version-
   Intel82547gi Version-
BeckhoffTwincat Version <= 3.1.0.3512
   BeckhoffTwincat Version3.1 Updatebuild_4022
   Intel82540em Version-
   Intel82540ep Version-
   Intel82541ei Version-
   Intel82541er Version-
   Intel82541gi Version-
   Intel82541pi Version-
   Intel82544ei Version-
   Intel82544gc Version-
   Intel82545em Version-
   Intel82545gm Version-
   Intel82546eb Version-
   Intel82546gb Version-
   Intel82547ei Version-
   Intel82547gi Version-
BeckhoffTwincat Version <= 2.11.0.2120
   BeckhoffTwincat Version2.11 Updatebuild_2350
   Intel82540em Version-
   Intel82540ep Version-
   Intel82541ei Version-
   Intel82541er Version-
   Intel82541gi Version-
   Intel82541pi Version-
   Intel82544ei Version-
   Intel82544gc Version-
   Intel82545em Version-
   Intel82545gm Version-
   Intel82546eb Version-
   Intel82546gb Version-
   Intel82547ei Version-
   Intel82547gi Version-
BeckhoffTwincat Version <= 3.1.0.3600
   BeckhoffTwincat Version3.1 Updatebuild_402
   Intel82557 Version-
   Intel82558 Version-
   Intel82559 Version-
BeckhoffTwincat Version <= 3.1.0.3500
   BeckhoffTwincat Version3.1 Updatebuild_4024
   Intel82557 Version-
   Intel82558 Version-
   Intel82559 Version-
BeckhoffTwincat Version <= 2.11.0.2117
   BeckhoffTwincat Version2.11 Updatebuild_2350
   Intel82557 Version-
   Intel82558 Version-
   Intel82559 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.561
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
info@cert.vde.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-459 Incomplete Cleanup

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.