VYPR
Vendor

Beckhoff

Products
10
CVEs
20
Across products
29
Status
Private

Products

10

Recent CVEs

20
  • CVE-2014-5414CriOct 5, 2016
    risk 0.60cvss 9.1epss 0.05

    Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

  • CVE-2017-16726CriJun 27, 2018
    risk 0.59cvss 9.1epss 0.01

    Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on…

  • CVE-2014-5415CriOct 5, 2016
    risk 0.59cvss 9.1epss 0.04

    Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Display service, or (3) TELNET service.

  • CVE-2018-7502HigMar 23, 2018
    risk 0.51cvss 7.8epss 0.01

    Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.

  • CVE-2017-16718MedJun 27, 2018
    risk 0.38cvss 5.9epss 0.00

    Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with…

  • CVE-2011-3486Sep 16, 2011
    risk 0.07cvss epss 0.51

    Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.

  • CVE-2024-41176Aug 27, 2024
    risk 0.00cvss epss 0.00

    The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.

  • CVE-2024-41175Aug 27, 2024
    risk 0.00cvss epss 0.00

    The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.

  • CVE-2024-41174Aug 27, 2024
    risk 0.00cvss epss 0.00

    The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

  • CVE-2024-41173Aug 27, 2024
    risk 0.00cvss epss 0.00

    The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

  • CVE-2023-6545Dec 14, 2023
    risk 0.00cvss epss 0.00

    The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.

  • CVE-2020-20741Jul 23, 2021
    risk 0.00cvss epss 0.02

    Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE…

  • CVE-2020-12526May 13, 2021
    risk 0.00cvss epss 0.01

    TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA…

  • CVE-2020-12510Nov 19, 2020
    risk 0.00cvss epss 0.01

    The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation…

  • CVE-2020-12494Jun 16, 2020
    risk 0.00cvss epss 0.01

    Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their…

  • CVE-2020-9464Mar 12, 2020
    risk 0.00cvss epss 0.01

    A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.

  • CVE-2019-16871Dec 19, 2019
    risk 0.00cvss epss 0.05

    Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.

  • CVE-2019-5637Nov 21, 2019
    risk 0.00cvss epss 0.01

    When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).

  • CVE-2019-5636Nov 21, 2019
    risk 0.00cvss epss 0.01

    When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).

  • CVE-2015-4051Jun 8, 2015
    risk 0.00cvss epss 0.06

    Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as…