Page 2 of 21 results (0.004 seconds)

CVSS: 8.5EPSS: 0%CPEs: 4EXPL: 0

TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system. TwinCAT OPC UA Server en TF6100 y TS6100 en versiones del producto anteriores a 4.3.48.0 o con versiones de TcOpcUaServer anteriores a 3.2.0.194, son propensos a un salto de ruta relativo que permite a administradores crear o eliminar cualquier archivo en el sistema • https://cert.vde.com/en/advisories/VDE-2021-051 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE side if the credentials are incorrect. Un Control de Acceso Incorrecto en Beckhoff Automation GmbH & Co. KG CX9020 con versiones de firmware CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6, permite a atacantes remotos omitir la autenticación por medio de "CE Remote Display Tool", ya que no cierra la conexión entrante en el lado de Windows CE si las credenciales son incorrectas • https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2019-006.pdf •

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs. • https://cert.vde.com/en-us/advisories/vde-2020-051 https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2021-001.pdf • CWE-20: Improper Input Validation •

CVSS: 7.3EPSS: 0%CPEs: 1EXPL: 0

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. • https://cert.vde.com/en-us/advisories/vde-2020-037 • CWE-276: Incorrect Default Permissions •

CVSS: 5.3EPSS: 0%CPEs: 63EXPL: 0

Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. • https://cert.vde.com/en-us/advisories/vde-2020-019 • CWE-459: Incomplete Cleanup •