CVE-2024-8934 – Beckhoff: Local command injection via TwinCAT Package Manager
https://notcve.org/view.php?id=CVE-2024-8934
31 Oct 2024 — A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed. • https://cert.vde.com/en/advisories/VDE-2024-064 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2024-41176 – Beckhoff: Local Denial of Service issue in package MDP included in TwinCAT/BSD
https://notcve.org/view.php?id=CVE-2024-41176
27 Aug 2024 — The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request. The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request. • https://cert.vde.com/en/advisories/VDE-2024-050 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2024-41175 – Beckhoff: Local Denial-of-Service vulnerability in TwinCAT/BSD and the IPC-Diagnostics package
https://notcve.org/view.php?id=CVE-2024-41175
27 Aug 2024 — The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker. • https://cert.vde.com/en/advisories/VDE-2024-049 • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2024-41174 – Beckhoff: Improper input neutralization vulnerability in the IPC-Diagnostics package in TwinCAT/BSD
https://notcve.org/view.php?id=CVE-2024-41174
27 Aug 2024 — The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker. • https://cert.vde.com/en/advisories/VDE-2024-048 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-41173 – Beckhoff: Local authentication bypass in the IPC-Diagnostics package included in TwinCAT/BSD
https://notcve.org/view.php?id=CVE-2024-41173
27 Aug 2024 — The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker. • https://cert.vde.com/en/advisories/VDE-2024-045 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •
CVE-2023-6545 – Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhf
https://notcve.org/view.php?id=CVE-2023-6545
14 Dec 2023 — The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia. El paquete authelia-bhf incluido en Beckhoffs TwinCAT/BSD es propenso a una redirección abierta que permite a un atacante remoto sin privilegios redirigir a un usuario a otro sitio. Esto puede tener un impacto limitado en la integridad ... • https://cert.vde.com/en/advisories/VDE-2023-067 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2021-34594 – Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server
https://notcve.org/view.php?id=CVE-2021-34594
04 Nov 2021 — TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system. TwinCAT OPC UA Server en TF6100 y TS6100 en versiones del producto anteriores a 4.3.48.0 o con versiones de TcOpcUaServer anteriores a 3.2.0.194, son propensos a un salto de ruta relativo que permite a administradores crear o eliminar cualquier archivo en el sistema • https://cert.vde.com/en/advisories/VDE-2021-051 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •
CVE-2020-20741
https://notcve.org/view.php?id=CVE-2020-20741
23 Jul 2021 — Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE side if the credentials are incorrect. Un Control de Acceso Incorrecto en Beckhoff Automation GmbH & Co. KG CX9020 con versiones de firmware CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6, permite a atacantes remotos omitir la autenticac... • https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2019-006.pdf •
CVE-2020-12526 – BECKHOFF: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Server
https://notcve.org/view.php?id=CVE-2020-12526
13 May 2021 — TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs. • https://cert.vde.com/en-us/advisories/vde-2020-051 • CWE-20: Improper Input Validation •
CVE-2020-12510 – Beckhoff: Privilege Escalation through TwinCat System
https://notcve.org/view.php?id=CVE-2020-12510
19 Nov 2020 — The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. • https://cert.vde.com/en-us/advisories/vde-2020-037 • CWE-276: Incorrect Default Permissions •