Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mdp Package HIGH 7.3
CVE-2024-41176

The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the d…

Fix: 1.2.7.0 / 14.1.2.0+
Fix from $1,950 2024-08-27
Ipc Diagnostics Package MEDIUM 5.5
CVE-2024-41175

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.

Fix: 2.0.0.1 / 14.1.2.0+
Fix from $1,600 2024-08-27
Ipc Diagnostics Package HIGH 7.8
CVE-2024-41173

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

Fix: 2.0.0.1 / 14.1.2.0+
Fix from $1,950 2024-08-27
Ipc Diagnostics Package HIGH 7.3
CVE-2024-41174

The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

Fix: 2.1.1.0 / 14.1.2.0+
Fix from $1,950 2024-08-27
Tf6100 Firmware MEDIUM 6.5
CVE-2021-34594

TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative…

Fix: 4.3.48.0+
Fix from $1,600 2021-11-04
Cx9020 CRITICAL 9.8
CVE-2020-20741

Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote att…

Patch available
Fix from $2,300 2021-07-23
Ipc Diagnostics Ua Server MEDIUM 5.3
CVE-2020-12526

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are v…

Fix: after 3.3.18
Fix from $1,600 2021-05-13
Twincat Extended Automation Runtime HIGH 7.3
CVE-2020-12510

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and furthe…

Mitigation only
Fix from $1,950 2020-11-19
Twincat Driver MEDIUM 5.3
CVE-2020-12494

Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except …

Fix: after 3.1.0.3603
Fix from $1,600 2020-06-16
Bk9000 Firmware HIGH 7.5
CVE-2020-9464

A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can…

No fix yet
Fix from $1,950 2020-03-12
Twincat CRITICAL 9.8
CVE-2019-16871EPSS 5%

Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Exe…

Fix: 3.1+
Fix from $2,300 2019-12-19
Twincat HIGH 7.5
CVE-2019-5636

When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still perfor…

No fix yet
Fix from $1,950 2019-11-21
Twincat HIGH 7.5
CVE-2019-5637

When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP pac…

No fix yet
Fix from $1,950 2019-11-21
Twincat CRITICAL 9.1
CVE-2017-16726

Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to…

Mitigation only
Fix from $2,300 2018-06-27
Twincat MEDIUM 5.9
CVE-2017-16718

Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user co…

No fix yet
Fix from $1,600 2018-06-27
Twincat HIGH 7.8
CVE-2018-7502

Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An…

Mitigation only
Fix from $1,950 2018-03-23
Embedded Pc Images CRITICAL 9.1
CVE-2014-5415

Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain acc…

Mitigation only
Fix from $2,300 2016-10-05
Embedded Pc Images CRITICAL 9.1
CVE-2014-5414

Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authenticati…

Mitigation only
Fix from $2,300 2016-10-05
Ipc Diagnostics HIGH 9.0
CVE-2015-4051EPSS 6%

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of ser…

Fix: after 1.7
Fix from $1,950 2015-06-08
Twincat MEDIUM 5.0
CVE-2011-3486EPSS 50%

Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers…

Fix: after 2.11.0.2004
Fix from $1,600 2011-09-16