Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2024-050
Mai 22, 2025, 3:03 nachm.
By default, TwinCAT/BSD-based products have a device-specific web interface for web-based management (WBM) enabled, developed by Beckhoff and known as Beckhoff Device Manager UI. It can be accessed remotely or …
VDE-2023-067
Mai 22, 2025, 3:03 nachm.
With TwinCAT/BSD based products the HTTPS request to the Authelia login page accepts user-controlled input that specifies a link to an external site.
VDE-2022-003
Juni 5, 2025, 3:28 nachm.
By tricking clients of the mentioned products into contacting malicious OPC UA servers and thereby acting as OPC UA clients, a crash of the component can be provoked.
VDE-2021-051
Mai 22, 2025, 3:03 nachm.
Through specific nodes of the server configuration interface of the TwinCAT OPC UA Server administrators are able to remotely create and delete any files on the system which the server …
VDE-2020-051
Mai 11, 2021, 12:00 nachm.
Some TwinCAT OPC UA Server and IPC Diagnostics UA Server versions from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send …
VDE-2020-037
Mai 22, 2025, 3:03 nachm.
The default installation path and its permissions for the TwinCAT runtime allow a local user to replace or modify executables other users of the same system might execute. The issue …
VDE-2020-019
Mai 22, 2025, 3:03 nachm.
Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet …
VDE-2020-005
Mai 22, 2025, 3:03 nachm.
The coupler's function could be inhibited by an attack.