Memory disclosure via uninitialized Ethernet frame padding
Published Jun 16, 2020 · Updated Aug 4, 2024
Information disclosure in Beckhoff TwinCAT RT Intel drivers allows remote attackers to read memory via short Ethernet frames. The Tcl8254x.sys and Tcl8255x.sys drivers transmit undersized frames without zeroing padding bytes, appending arbitrary kernel memory. An unauthenticated network peer can provoke responses with small ICMP echo requests, but cannot reliably control which remnants of prior traffic are returned.
Summary
What happened
Information disclosure in Beckhoff TwinCAT RT Intel drivers allows remote attackers to read memory via short Ethernet frames. The Tcl8254x.sys and Tcl8255x.sys drivers transmit undersized frames without zeroing padding bytes, appending arbitrary kernel memory. An unauthenticated network peer can provoke responses with small ICMP echo requests, but cannot reliably control which remnants of prior traffic are returned.
The record
- CVE
- CVE-2020-12494
- Published
- Jun 16, 2020
- Updated
- Aug 4, 2024
- Vendor
- Beckhoff Automation GmbH & Co. KG
- Product
- TwinCAT Driver for Intel 8255x
- Classifications
- CWE-459, T1040
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jun 16, 2020CVE publishedPublication date reported by the CVE source.
- Aug 4, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=unspecified <=2.11.0.2117 for TwinCAT 2.11 2350
- Affected versionversion=unspecified <=3.1.0.3500 for TwinCAT 3.1 4024
- Affected versionversion=unspecified <=3.1.0.3600 for TwinCAT 3.1 4024
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo