// For flags

CVE-2019-5637

Beckhoff TwinCAT Profinet Driver Divide-by-Zero Denial of Service

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).

Cuando Beckhoff TwinCAT está configurado para usar el controlador Profinet, se puede llegar a una denegación de servicio del controlador enviando un paquete UDP con formato incorrecto al dispositivo. Este problema afecta a TwinCAT 2 versión 2304 (y anterior) y TwinCAT 3.1 versión 4204.0 (y anterior).

*Credits: This issue was discovered, and reported to Rapid7, by Andreas Galauner at Rapid7. It is being disclosed in accordance with Rapid7's vulnerability disclosure policy (https://www.rapid7.com/disclosure/).
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-07 CVE Reserved
  • 2019-11-21 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-369: Divide By Zero
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Beckhoff
Search vendor "Beckhoff"
Twincat
Search vendor "Beckhoff" for product "Twincat"
3.1.4022.30
Search vendor "Beckhoff" for product "Twincat" and version "3.1.4022.30"
-
Affected
in Beckhoff
Search vendor "Beckhoff"
Twincat Cx2030
Search vendor "Beckhoff" for product "Twincat Cx2030"
--
Safe
Beckhoff
Search vendor "Beckhoff"
Twincat
Search vendor "Beckhoff" for product "Twincat"
3.1.4022.30
Search vendor "Beckhoff" for product "Twincat" and version "3.1.4022.30"
-
Affected
in Beckhoff
Search vendor "Beckhoff"
Twincat Cx5140
Search vendor "Beckhoff" for product "Twincat Cx5140"
--
Safe
Beckhoff
Search vendor "Beckhoff"
Twincat
Search vendor "Beckhoff" for product "Twincat"
3.1.4022.29
Search vendor "Beckhoff" for product "Twincat" and version "3.1.4022.29"
-
Affected
in Beckhoff
Search vendor "Beckhoff"
Twincat Cx5140
Search vendor "Beckhoff" for product "Twincat Cx5140"
--
Safe