Beckhoff records
22 published records for vendor beckhoff.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 4.5%
- Pre-auth RCE
- 1
- With a fix record
- 27.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-20 Improper Input Validation1
- CWE-23 Relative Path Traversal1
- CWE-276 Incorrect Default Permissions1
- CWE-284 Improper Access Control1
- CWE-285 Improper Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2019-16871No exploit | Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remotebeckhoff · twincat · CWE-290 | Critical9.8 | — | 5.3% | Dec 19, 2019 |
39Monitor | CVE-2020-20741No exploit | Incorrect Access Control in Beckhoff Automation GmbH & Co.beckhoff · cx9020 | Critical9.8 | — | 1.6% | Jul 23, 2021 |
38Monitor | CVE-2015-4051No exploit | Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denibeckhoff · ipc diagnostics · CWE-284 | Critical9.0 | — | 5.7% | Jun 8, 2015 |
37Monitor | CVE-2014-5414No exploit | Beckhoff Embedded PC Images and TwinCAT Components Improper Restriction of Excessive Authentication Attemptsbeckhoff · embedded pc images · CWE-307 | Critical9.1 | — | 4.8% | Oct 5, 2016 |
37Monitor | CVE-2014-5415No exploit | Beckhoff Embedded PC Images and TwinCAT Components Exposed Dangerous Method or Functionbeckhoff · embedded pc images · CWE-749 | Critical9.1 | — | 4.3% | Oct 5, 2016 |
36Monitor | CVE-2017-16726No exploit | Beckhoff TwinCAT supports communication over ADS.beckhoff · twincat · CWE-285 | Critical9.1 | — | 0.5% | Jun 27, 2018 |
35Monitor | CVE-2011-3486Weaponized | Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, whichbeckhoff · twincat · CWE-119 | Medium5.0 | — | 49.7% | Sep 16, 2011 |
31Monitor | CVE-2018-7502No exploit | Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer vbeckhoff · twincat · CWE-822 | High7.8 | — | 0.6% | Mar 23, 2018 |
31Monitor | CVE-2024-41173No exploit | Beckhoff: Local authentication bypass in the IPC-Diagnostics package included in TwinCAT/BSDbeckhoff · ipc diagnostics package · CWE-288 | High7.8 | — | 0.2% | Aug 27, 2024 |
30Monitor | CVE-2019-5636No exploit | Beckhoff TwinCAT Discovery Service Denial of Servicebeckhoff · twincat · CWE-404 | High7.5 | — | 1.4% | Nov 21, 2019 |
30Monitor | CVE-2019-5637No exploit | Beckhoff TwinCAT Profinet Driver Divide-by-Zero Denial of Servicebeckhoff · twincat · CWE-369 | High7.5 | — | 1.4% | Nov 21, 2019 |
30Monitor | CVE-2020-9464No exploit | A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000.beckhoff · bk9000 firmware · CWE-400 | High7.5 | — | 1.4% | Mar 12, 2020 |
29Monitor | CVE-2020-12510No exploit | Beckhoff: Privilege Escalation through TwinCat Systembeckhoff · twincat extended automation runtime · CWE-276 | High7.3 | — | 0.9% | Nov 19, 2020 |
29Monitor | CVE-2024-41176No exploit | Beckhoff: Local Denial of Service issue in package MDP included in TwinCAT/BSDbeckhoff · mdp package · CWE-120 | High7.3 | — | 0.3% | Aug 27, 2024 |
29Monitor | CVE-2024-41174No exploit | Beckhoff: Improper input neutralization vulnerability in the IPC-Diagnostics package in TwinCAT/BSDbeckhoff · ipc diagnostics package · CWE-79 | High7.3 | — | 0.2% | Aug 27, 2024 |
26Monitor | CVE-2021-34594No exploit | Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Serverbeckhoff · tf6100 firmware · CWE-23 | Medium6.5 | — | 1.1% | Nov 4, 2021 |
26Monitor | CVE-2024-8934No exploit | Beckhoff: Local command injection via TwinCAT Package Managerbeckhoff · twincat package manager · CWE-78 | Medium6.5 | — | 0.2% | Oct 31, 2024 |
23Monitor | CVE-2017-16718No exploit | Beckhoff TwinCAT 3 supports communication over ADS.beckhoff · twincat · CWE-522 | Medium5.9 | — | 0.4% | Jun 27, 2018 |
22Monitor | CVE-2024-41175No exploit | Beckhoff: Local Denial-of-Service vulnerability in TwinCAT/BSD and the IPC-Diagnostics packagebeckhoff · ipc diagnostics package · CWE-770 | Medium5.5 | — | 0.2% | Aug 27, 2024 |
21Monitor | CVE-2020-12494No exploit | Beckhoff: Etherleak in TwinCAT RT network driverbeckhoff · twincat driver · CWE-459 | Medium5.3 | — | 1.0% | Jun 16, 2020 |
21Monitor | CVE-2020-12526No exploit | BECKHOFF: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Serverbeckhoff · ipc diagnostics ua server · CWE-20 | Medium5.3 | — | 1.0% | May 13, 2021 |
18Monitor | CVE-2023-6545No exploit | Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhfbeckhoff · authelia-bhf · CWE-601 | Medium4.7 | — | 0.4% | Dec 14, 2023 |
- CVE-2019-1687141Plan
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote
CriticalCVSS 9.8No exploitEPSS 5%beckhoff · twincatDec 19, 2019
- CVE-2020-2074139Monitor
Incorrect Access Control in Beckhoff Automation GmbH & Co.
CriticalCVSS 9.8No exploitEPSS 2%beckhoff · cx9020Jul 23, 2021
- CVE-2015-405138Monitor
Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a deni
CriticalCVSS 9.0No exploitEPSS 6%beckhoff · ipc diagnosticsJun 8, 2015
- CVE-2014-541437Monitor
Beckhoff Embedded PC Images and TwinCAT Components Improper Restriction of Excessive Authentication Attempts
CriticalCVSS 9.1No exploitEPSS 5%beckhoff · embedded pc imagesOct 5, 2016
- CVE-2014-541537Monitor
Beckhoff Embedded PC Images and TwinCAT Components Exposed Dangerous Method or Function
CriticalCVSS 9.1No exploitEPSS 4%beckhoff · embedded pc imagesOct 5, 2016
- CVE-2017-1672636Monitor
Beckhoff TwinCAT supports communication over ADS.
CriticalCVSS 9.1No exploitEPSS 1%beckhoff · twincatJun 27, 2018
- CVE-2011-348635Monitor
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which
MediumCVSS 5.0WeaponizedEPSS 50%beckhoff · twincatSep 16, 2011
- CVE-2018-750231Monitor
Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer v
HighCVSS 7.8No exploitEPSS 1%beckhoff · twincatMar 23, 2018
- CVE-2024-4117331Monitor
Beckhoff: Local authentication bypass in the IPC-Diagnostics package included in TwinCAT/BSD
HighCVSS 7.8No exploitEPSS 0%beckhoff · ipc diagnostics packageAug 27, 2024
- CVE-2019-563630Monitor
Beckhoff TwinCAT Discovery Service Denial of Service
HighCVSS 7.5No exploitEPSS 1%beckhoff · twincatNov 21, 2019
- CVE-2019-563730Monitor
Beckhoff TwinCAT Profinet Driver Divide-by-Zero Denial of Service
HighCVSS 7.5No exploitEPSS 1%beckhoff · twincatNov 21, 2019
- CVE-2020-946430Monitor
A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000.
HighCVSS 7.5No exploitEPSS 1%beckhoff · bk9000 firmwareMar 12, 2020
- CVE-2020-1251029Monitor
Beckhoff: Privilege Escalation through TwinCat System
HighCVSS 7.3No exploitEPSS 1%beckhoff · twincat extended automation runtimeNov 19, 2020
- CVE-2024-4117629Monitor
Beckhoff: Local Denial of Service issue in package MDP included in TwinCAT/BSD
HighCVSS 7.3No exploitEPSS 0%beckhoff · mdp packageAug 27, 2024
- CVE-2024-4117429Monitor
Beckhoff: Improper input neutralization vulnerability in the IPC-Diagnostics package in TwinCAT/BSD
HighCVSS 7.3No exploitEPSS 0%beckhoff · ipc diagnostics packageAug 27, 2024
- CVE-2021-3459426Monitor
Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server
MediumCVSS 6.5No exploitEPSS 1%beckhoff · tf6100 firmwareNov 4, 2021
- CVE-2024-893426Monitor
Beckhoff: Local command injection via TwinCAT Package Manager
MediumCVSS 6.5No exploitEPSS 0%beckhoff · twincat package managerOct 31, 2024
- CVE-2017-1671823Monitor
Beckhoff TwinCAT 3 supports communication over ADS.
MediumCVSS 5.9No exploitEPSS 0%beckhoff · twincatJun 27, 2018
- CVE-2024-4117522Monitor
Beckhoff: Local Denial-of-Service vulnerability in TwinCAT/BSD and the IPC-Diagnostics package
MediumCVSS 5.5No exploitEPSS 0%beckhoff · ipc diagnostics packageAug 27, 2024
- CVE-2020-1249421Monitor
Beckhoff: Etherleak in TwinCAT RT network driver
MediumCVSS 5.3No exploitEPSS 1%beckhoff · twincat driverJun 16, 2020
- CVE-2020-1252621Monitor
BECKHOFF: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Server
MediumCVSS 5.3No exploitEPSS 1%beckhoff · ipc diagnostics ua serverMay 13, 2021
- CVE-2023-654518Monitor
Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhf
MediumCVSS 4.7No exploitEPSS 0%beckhoff · authelia-bhfDec 14, 2023