CVE-2024-41175 – Beckhoff: Local Denial-of-Service vulnerability in TwinCAT/BSD and the IPC-Diagnostics package
https://notcve.org/view.php?id=CVE-2024-41175
27 Aug 2024 — The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker. • https://cert.vde.com/en/advisories/VDE-2024-049 • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2024-41174 – Beckhoff: Improper input neutralization vulnerability in the IPC-Diagnostics package in TwinCAT/BSD
https://notcve.org/view.php?id=CVE-2024-41174
27 Aug 2024 — The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker. • https://cert.vde.com/en/advisories/VDE-2024-048 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-41173 – Beckhoff: Local authentication bypass in the IPC-Diagnostics package included in TwinCAT/BSD
https://notcve.org/view.php?id=CVE-2024-41173
27 Aug 2024 — The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker. • https://cert.vde.com/en/advisories/VDE-2024-045 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •
CVE-2020-12526 – BECKHOFF: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Server
https://notcve.org/view.php?id=CVE-2020-12526
13 May 2021 — TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs. • https://cert.vde.com/en-us/advisories/vde-2020-051 • CWE-20: Improper Input Validation •
CVE-2015-4051 – Beckoff CX9020 CPU Model Remote Code Execution
https://notcve.org/view.php?id=CVE-2015-4051
05 Jun 2015 — Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi. Beckhoff IPC Diagnostics anterior a 1.8 no restringe correctamente el acceso a funciones en /config, lo que permite a atacantes remotos causar una denegación de ... • http://ftp.beckhoff.com/download/document/IndustPC/Advisory-2015-001.pdf • CWE-284: Improper Access Control •