CVE Database
/

CVE-2017-16718

Back to search

CVE-2017-16718

Published: Jun 27, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.

VendorProductVersions

ICS-CERT

Beckhoff TwinCAT

affected
Version 3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now