CVE-2019-16871
9.8
CRITICAL · CVSS 3.1 · EPSS 5.3% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.3% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-290 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-12-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| beckhoff | twincat |
References
- https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2017-001.pdf
- https://www.ic4.be/2019/12/18/beckhoff-cve-2019-16871/#more-648
- https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2017-001.pdf
- https://www.ic4.be/2019/12/18/beckhoff-cve-2019-16871/#more-648
→ the Explorer · watch your stack · NVD