{ "schema_version": "1.4.0", "id": "GHSA-v98p-fx5c-967q", "modified": "2022-05-14T03:21:41Z", "published": "2022-05-14T03:21:41Z", "aliases": [ "CVE-2018-7502" ], "details": "Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-7502" }, { "type": "WEB", "url": "https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2018-001.pdf" }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-081-02" }, { "type": "WEB", "url": "https://srcincite.io/advisories/src-2018-0007" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/103487" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2018-03-23T17:29:00Z" } }