CVE Feed

    Dashboard / CVE / CVE-2020-12494

    CVE-2020-12494

    Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device.

    Published:Jun 16, 2020
    Last Modified:Nov 21, 2024
    EPS:Jun 16, 2020
    EPSS Score:0.00339
    CVSS Score:5.3

    Affected Products

    Vendor
    Beckhoff
    Product
    Twincat
    Vendor
    Beckhoff
    Product
    Twincat Driver
    Vendor
    Intel
    Product
    82540em
    Vendor
    Intel
    Product
    82540ep
    Vendor
    Intel
    Product
    82541ei
    Vendor
    Intel
    Product
    82541er
    Vendor
    Intel
    Product
    82541gi
    Vendor
    Intel
    Product
    82541pi
    Vendor
    Intel
    Product
    82544ei
    Vendor
    Intel
    Product
    82544gc
    Vendor
    Intel
    Product
    82545em
    Vendor
    Intel
    Product
    82545gm
    Vendor
    Intel
    Product
    82546eb
    Vendor
    Intel
    Product
    82546gb
    Vendor
    Intel
    Product
    82547ei
    Vendor
    Intel
    Product
    82547ei
    Vendor
    Intel
    Product
    82547gi
    Vendor
    Intel
    Product
    82557
    Vendor
    Intel
    Product
    82558
    Vendor
    Intel
    Product
    82559

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High