Beckhoff Embedded PC Images and TwinCAT Components Improper Restriction of Excessive Authentication Attempts
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.1epss 4.8%
probabilidad de explotación
4.8%top 9% de las CVE
explotación observada
noninguna fuente lo reporta
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Beckhoff · Embedded PC ImagesBeckhoff · TwinCAT Components featuring Automation Device Specification (ADS) communicationReferencias
https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2014-001.pdfhttps://download.beckhoff.com/download/document/product-security/Advisories/advisory-2014-002.pdfhttps://download.beckhoff.com/download/document/product-security/Advisories/advisory-2014-003.pdfhttps://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2016/icsa-16-278-02.jsonhttps://ics-cert.us-cert.gov/advisories/ICSA-16-278-02https://www.cisa.gov/news-events/ics-advisories/icsa-16-278-02http://www.securityfocus.com/bid/93349