{"id": "CVE-2020-12494", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "info@cert.vde.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 3.9}]}, "published": "2020-06-16T14:15:10.977", "references": [{"url": "https://cert.vde.com/en-us/advisories/vde-2020-019", "tags": ["Third Party Advisory"], "source": "info@cert.vde.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "info@cert.vde.com", "description": [{"lang": "en", "value": "CWE-459"}]}, {"type": "Secondary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-459"}]}], "descriptions": [{"lang": "en", "value": "Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device."}, {"lang": "es", "value": "El controlador de red TwinCAT RT de Beckhoff para Intel 8254x y 8255x, proporciona la funcionalidad EtherCAT. El controlador implementa caracter\u00edsticas en tiempo real. A excepci\u00f3n de las tramas Ethernet enviadas desde la funcionalidad en tiempo real, todas las dem\u00e1s tramas Ethernet enviadas por medio del controlador no son rellenadas si su carga \u00fatil es menor que el tama\u00f1o m\u00ednimo de trama Ethernet. En su lugar, el contenido de memoria arbitrario es transmitido dentro de los bytes de relleno de la trama. Lo m\u00e1s probable es que esta memoria contenga segmentos de tramas transmitidas o recibidas previamente. Mediante este m\u00e9todo, se revela el contenido de la memoria, sin embargo, un atacante apenas puede controlar qu\u00e9 contenido de la memoria est\u00e1 afectado. Por ejemplo, la divulgaci\u00f3n puede ser provocada con peticiones echo ICMP de peque\u00f1o tama\u00f1o enviadas al dispositivo"}], "lastModified": "2021-12-02T19:31:54.420", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat_driver:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA181C43-953B-483C-B34E-74089B1F56E2", "versionEndIncluding": "3.1.0.3603"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:3.1:build_4024:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "833123D8-C8C4-4F0B-84E4-34149B0FFA67"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:intel:82540em:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "50C24972-C85A-4B9D-B49B-64959A3D6EA8"}, {"criteria": "cpe:2.3:h:intel:82540ep:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F0A7B7D2-1889-4B31-A71D-6128D56A1E98"}, {"criteria": "cpe:2.3:h:intel:82541ei:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0FF5DE70-0AFB-4C98-B394-CC01ABCC05CE"}, {"criteria": "cpe:2.3:h:intel:82541er:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83789ECA-6CF4-4851-814B-8F3BA1B3C924"}, {"criteria": "cpe:2.3:h:intel:82541gi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AB515EAE-EA1B-4095-B98E-B993DE5478E0"}, {"criteria": "cpe:2.3:h:intel:82541pi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C5722E6B-39F4-4B55-B823-0168E8206685"}, {"criteria": "cpe:2.3:h:intel:82544ei:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "73A17337-9AA4-440C-BBDE-6022FDAB6630"}, {"criteria": "cpe:2.3:h:intel:82544gc:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5E7FC2A9-9EA6-4B40-A768-E0F2E2B0BA01"}, {"criteria": "cpe:2.3:h:intel:82545em:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7191B4EF-281A-47C9-9BD0-EC1BA936814A"}, {"criteria": "cpe:2.3:h:intel:82545gm:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "955D2173-8388-4CD7-8481-05D16F499ED7"}, {"criteria": "cpe:2.3:h:intel:82546eb:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "52BF5F63-57A5-4794-A8B4-FE38A330FAE9"}, {"criteria": "cpe:2.3:h:intel:82546gb:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8D7D6376-7FEC-43C7-AC1B-F5BB0AFACD24"}, {"criteria": "cpe:2.3:h:intel:82547ei:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CAD4C9C7-165D-432A-9FB1-00599AB53632"}, {"criteria": "cpe:2.3:h:intel:82547gi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6EB8DA28-02A2-4921-BC0A-B4F41CD033BB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28813786-BC07-4F45-81DD-6C82E993EBB1", "versionEndIncluding": "3.1.0.3512"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:3.1:build_4022:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A30C25C0-DF20-4F75-B054-04CB69E4828B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:intel:82540em:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "50C24972-C85A-4B9D-B49B-64959A3D6EA8"}, {"criteria": "cpe:2.3:h:intel:82540ep:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F0A7B7D2-1889-4B31-A71D-6128D56A1E98"}, {"criteria": "cpe:2.3:h:intel:82541ei:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0FF5DE70-0AFB-4C98-B394-CC01ABCC05CE"}, {"criteria": "cpe:2.3:h:intel:82541er:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83789ECA-6CF4-4851-814B-8F3BA1B3C924"}, {"criteria": "cpe:2.3:h:intel:82541gi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AB515EAE-EA1B-4095-B98E-B993DE5478E0"}, {"criteria": "cpe:2.3:h:intel:82541pi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C5722E6B-39F4-4B55-B823-0168E8206685"}, {"criteria": "cpe:2.3:h:intel:82544ei:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "73A17337-9AA4-440C-BBDE-6022FDAB6630"}, {"criteria": "cpe:2.3:h:intel:82544gc:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5E7FC2A9-9EA6-4B40-A768-E0F2E2B0BA01"}, {"criteria": "cpe:2.3:h:intel:82545em:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7191B4EF-281A-47C9-9BD0-EC1BA936814A"}, {"criteria": "cpe:2.3:h:intel:82545gm:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "955D2173-8388-4CD7-8481-05D16F499ED7"}, {"criteria": "cpe:2.3:h:intel:82546eb:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "52BF5F63-57A5-4794-A8B4-FE38A330FAE9"}, {"criteria": "cpe:2.3:h:intel:82546gb:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8D7D6376-7FEC-43C7-AC1B-F5BB0AFACD24"}, {"criteria": "cpe:2.3:h:intel:82547ei_:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "127BA9B4-1AC8-4E2A-B988-A6DB74D94005"}, {"criteria": "cpe:2.3:h:intel:82547gi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6EB8DA28-02A2-4921-BC0A-B4F41CD033BB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDAC8A5E-E88D-446D-8259-3DE668C733BF", "versionEndIncluding": "2.11.0.2120"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:2.11:build_2350:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "65A29D14-486E-47E4-AEBC-8F1B61AE3C96"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:intel:82540em:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "50C24972-C85A-4B9D-B49B-64959A3D6EA8"}, {"criteria": "cpe:2.3:h:intel:82540ep:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F0A7B7D2-1889-4B31-A71D-6128D56A1E98"}, {"criteria": "cpe:2.3:h:intel:82541ei:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0FF5DE70-0AFB-4C98-B394-CC01ABCC05CE"}, {"criteria": "cpe:2.3:h:intel:82541er:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83789ECA-6CF4-4851-814B-8F3BA1B3C924"}, {"criteria": "cpe:2.3:h:intel:82541gi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AB515EAE-EA1B-4095-B98E-B993DE5478E0"}, {"criteria": "cpe:2.3:h:intel:82541pi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C5722E6B-39F4-4B55-B823-0168E8206685"}, {"criteria": "cpe:2.3:h:intel:82544ei:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "73A17337-9AA4-440C-BBDE-6022FDAB6630"}, {"criteria": "cpe:2.3:h:intel:82544gc:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5E7FC2A9-9EA6-4B40-A768-E0F2E2B0BA01"}, {"criteria": "cpe:2.3:h:intel:82545em:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7191B4EF-281A-47C9-9BD0-EC1BA936814A"}, {"criteria": "cpe:2.3:h:intel:82545gm:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "955D2173-8388-4CD7-8481-05D16F499ED7"}, {"criteria": "cpe:2.3:h:intel:82546eb:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "52BF5F63-57A5-4794-A8B4-FE38A330FAE9"}, {"criteria": "cpe:2.3:h:intel:82546gb:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8D7D6376-7FEC-43C7-AC1B-F5BB0AFACD24"}, {"criteria": "cpe:2.3:h:intel:82547ei_:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "127BA9B4-1AC8-4E2A-B988-A6DB74D94005"}, {"criteria": "cpe:2.3:h:intel:82547gi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6EB8DA28-02A2-4921-BC0A-B4F41CD033BB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B2487EF-FA8E-47B7-B64E-C85074E41A5C", "versionEndIncluding": "3.1.0.3600"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:3.1:build_402:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DEFD2024-2C25-4CF2-8594-D5FFA6F37D4A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:intel:82557:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B15B3AE8-CE85-4859-917F-7761D4C7E0EA"}, {"criteria": "cpe:2.3:h:intel:82558:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AEF15ABE-3181-46C6-A77E-01AF0F654E11"}, {"criteria": "cpe:2.3:h:intel:82559:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7E20AD23-1608-4BC4-A3B3-9BF6ED7975DC"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34EE5CBB-16DA-4047-B91B-E0EA9A88BF06", "versionEndIncluding": "3.1.0.3500"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:3.1:build_4024:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "833123D8-C8C4-4F0B-84E4-34149B0FFA67"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:intel:82557:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B15B3AE8-CE85-4859-917F-7761D4C7E0EA"}, {"criteria": "cpe:2.3:h:intel:82558:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AEF15ABE-3181-46C6-A77E-01AF0F654E11"}, {"criteria": "cpe:2.3:h:intel:82559:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7E20AD23-1608-4BC4-A3B3-9BF6ED7975DC"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2B6E51B-FDD5-40F4-BBA7-FF2922696D5E", "versionEndIncluding": "2.11.0.2117"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:beckhoff:twincat:2.11:build_2350:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "65A29D14-486E-47E4-AEBC-8F1B61AE3C96"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:intel:82557:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B15B3AE8-CE85-4859-917F-7761D4C7E0EA"}, {"criteria": "cpe:2.3:h:intel:82558:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AEF15ABE-3181-46C6-A77E-01AF0F654E11"}, {"criteria": "cpe:2.3:h:intel:82559:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7E20AD23-1608-4BC4-A3B3-9BF6ED7975DC"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "info@cert.vde.com"}