<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_beckhoffautomationgmbhcokg/10</id>
  <title>Most recent entries from csaf_beckhoffautomationgmbhcokg</title>
  <updated>2026-10-02T09:07:49.590657+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-019</id>
    <title>VDE-2019-019 — Beckhoff: TwinCAT Denial-of-Service in Profinet driver</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In case TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending special packets to the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-019"/>
    <published>2019-10-09T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-005</id>
    <title>VDE-2020-005 — Beckhoff: BK9000 couplers - Denial of service inhibits function</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The coupler's function could be inhibited by an attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-005"/>
    <published>2020-03-10T13:17:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-019</id>
    <title>VDE-2020-019 — Beckhoff: EtherLeak in TwinCAT RT network driver</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-019"/>
    <published>2020-06-16T08:31:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-037</id>
    <title>VDE-2020-037 — Beckhoff: Privilege Escalation through TwinCat System Tray (TcSysUI.exe)</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The default installation path and its permissions for the TwinCAT runtime allow a local user to replace or modify executables other users of the same system might execute. The issue does not apply for installations underneath C:\Program Files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-037"/>
    <published>2020-11-19T13:41:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-051</id>
    <title>VDE-2020-051 — Beckhoff: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Server</title>
    <updated>2021-05-11T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Some TwinCAT OPC UA Server and IPC Diagnostics UA Server versions from Beckhoff Automation GmbH &amp; Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.</p>
<p>UPDATE A - 11.05.2021</p>
<p>Please note that some hardware products from Beckhoff are shipped with a TwinCAT OPC UA Server pre-installed. In some cases the server is enabled by default.</p>
<p>IPC Diagnostics UA Server (contained in Beckhoff's Windows images)</p>
<p>server versions up to and including 3.1.0.1 are affected
Please note that IPC products from Beckhoff are shipped with an IPC Diagnostics UA Server pre-installed. In all cases the server is disabled by default.
The version numbers named above always refer to the version number which is accessible via OPC UA at the server via the standard OPC UA node /Objects/Server/ServerStatus/BuildInfo/SoftwareVersion and on Windows also as the file property "File version" of the file TcOpcUaServer.exe for TwinCAT OPC UA Server respectively the file DevMgrSvr-UA.exe for IPC Diagnostics UA Server.</p>
<p>UPDATE A - 11.05.2021</p>
<p>Please note that IPC products from Beckhoff are shipped with an IPC Diagnostics UA Server pre-installed. While on Windows CE it is disabled by default all other Windows images have it enabled by default.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-051"/>
    <published>2021-04-27T08:08:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-051</id>
    <title>VDE-2021-051 — Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-051"/>
    <published>2021-11-04T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-003</id>
    <title>VDE-2022-003 — BECKHOFF: Null Pointer Dereference vulnerability in products with OPC UA technology</title>
    <updated>2025-06-05T13:28:13+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>By tricking clients of the mentioned products into contacting malicious OPC UA servers and thereby acting as OPC UA clients, a crash of the component can be provoked.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-003"/>
    <published>2022-03-01T12:34:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-067</id>
    <title>VDE-2023-067 — Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhf</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-067"/>
    <published>2023-12-13T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-045</id>
    <title>VDE-2024-045 — Beckhoff: Local authentication bypass in IPC-Diagnostics package included in TwinCAT/BSD operating system</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-045"/>
    <published>2024-08-27T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-048</id>
    <title>VDE-2024-048 — Beckhoff: Improper neutralization of input in IPC-Diagnostics-www package included in TwinCAT/BSD operating system</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The IPC-Diagnostics-www package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-048"/>
    <published>2024-08-27T08:00:00+00:00</published>
  </entry>
</feed>
