cbcvebase.

Beckhoff Twincat vulnerabilities

7 known vulnerabilities affecting beckhoff/twincat.

Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2011-3486P3MEDIUMCVSS 5.0PoC≤ 2.11.0.2004v2.7+3 more2011-09-16
CVE-2011-3486 [MEDIUM] CWE-119 CVE-2011-3486: Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.
nvd
CVE-2019-16871P2CRITICALCVSS 9.8≥ 3.0, < 3.1v2.0+1 more2019-12-19
CVE-2019-16871 [CRITICAL] CWE-290 CVE-2019-16871: Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stati Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
nvd
CVE-2018-7502P3HIGHCVSS 7.8v2.11v3.12018-03-23
CVE-2018-7502 [HIGH] CWE-822 CVE-2018-7502: Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack prop Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.
nvd
CVE-2019-5637P3HIGHCVSS 7.5v3.1.4022.30v3.1.4022.292019-11-21
CVE-2019-5637 [HIGH] CWE-369 CVE-2019-5637: When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controlle When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).
nvd
CVE-2019-5636P3HIGHCVSS 7.5v2.0v3.12019-11-21
CVE-2019-5636 [HIGH] CWE-404 CVE-2019-5636: When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts dow When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).
nvd
CVE-2017-16718P4MEDIUMCVSS 5.9v3.02018-06-27
CVE-2017-16718 [MEDIUM] CWE-522 CVE-2017-16718: Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in p Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attack
nvd
CVE-2020-12494P4MEDIUMCVSS 5.3≤ 3.1.0.3512≤ 2.11.0.2120+3 more2020-06-16
CVE-2020-12494 [MEDIUM] CWE-459 CVE-2020-12494: Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary m
nvd
Beckhoff Twincat vulnerabilities | cvebase