Vulnerability Description
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Beckhoff | Twincat | 2.0 |
Related Weaknesses (CWE)
References
- https://blog.rapid7.com/2019/10/08/r7-2019-32-denial-of-service-vulnerabilities-ExploitThird Party Advisory
- https://download.beckhoff.com/download/Document/product-security/Advisories/adviVendor Advisory
- https://blog.rapid7.com/2019/10/08/r7-2019-32-denial-of-service-vulnerabilities-ExploitThird Party Advisory
- https://download.beckhoff.com/download/Document/product-security/Advisories/adviVendor Advisory
FAQ
What is CVE-2019-5636?
CVE-2019-5636 is a vulnerability with a CVSS score of 5.3 (MEDIUM). When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affects TwinCAT 2 versio...
How severe is CVE-2019-5636?
CVE-2019-5636 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5636?
Check the references section above for vendor advisories and patch information. Affected products include: Beckhoff Twincat.