<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_beckhoffautomationgmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:11:48 +0000</lastBuildDate>
    <item>
      <title>VDE-2025-106 — Beckhoff: XSS Vulnerability in TwinCAT 3 HMI Server</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-106</link>
      <description>&lt;p&gt;An optional package of the TwinCAT 3 XAR installs the TwinCAT 3 HMI Server on a device. It provides a server configuration page which can be accessed by administrative users only. When such an administrator accesses the server configuration page it is possible to upload arbitrary content into the CUSTOM_CSS field which is then persisted on the device and later returned and rendered with each login and error page.
Please note that administrators have the access rights to modify any content on the HMI server, for example, via the server configuration page. Therefore, administrators would have to act maliciously to exploit this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An optional package of the TwinCAT 3 XAR installs the TwinCAT 3 HMI Server on a device. It provides a server configuration page which can be accessed by administrative users only. When such an administrator accesses the server configuration page it is possible to upload arbitrary content into the CUSTOM_CSS field which is then persisted on the device and later returned and rendered with each login and error page.
Please note that administrators have the access rights to modify any content on the HMI server, for example, via the server configuration page. Therefore, administrators would have to act maliciously to exploit this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-106</guid>
      <pubDate>Mon, 26 Jan 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-092 — Beckhoff: Privilege escalation and information leak via Beckhoff Device Manager</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-092</link>
      <description>&lt;p&gt;The vulnerability CVE-2025-41726 (NN-2025-0074) allows an authenticated remote user to execute arbitrary commands on the device. This can be exploited over the web UI or via API. In one case the execution of the arbitrary command happens within a privileged process.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41727 (NN-2025-0075) allows a local user with low privileges on the device to bypass the authentication mechanism of the UI and send commands to a privileged process which it executes on behalf of that user but with higher privileges. This way the local user can escalate privileges.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41728 (NN-2025-0076) allows an authenticated remote user to cause an out-of-bounds read operation within a specific service process which runs on the device. The read operation might copy sensitive information from the memory of the specific service into a response message which is then provided to the user but the user cannot choose which information is disclosed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerability CVE-2025-41726 (NN-2025-0074) allows an authenticated remote user to execute arbitrary commands on the device. This can be exploited over the web UI or via API. In one case the execution of the arbitrary command happens within a privileged process.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41727 (NN-2025-0075) allows a local user with low privileges on the device to bypass the authentication mechanism of the UI and send commands to a privileged process which it executes on behalf of that user but with higher privileges. This way the local user can escalate privileges.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41728 (NN-2025-0076) allows an authenticated remote user to cause an out-of-bounds read operation within a specific service process which runs on the device. The read operation might copy sensitive information from the memory of the specific service into a response message which is then provided to the user but the user cannot choose which information is disclosed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-092</guid>
      <pubDate>Tue, 27 Jan 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-075 — Beckhoff: Deserialization of untrusted data by TwinCAT 3 Engineering</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-075</link>
      <description>&lt;p&gt;Beckhoff&amp;#39;s TwinCAT 3 Engineering software is intented to craft automation projects consisting of a set of files which are stored locally as files underneath an individual folder or in a packed file. The TwinCAT 3 Engineering stores user settings and preferences among the non packed local files which are relevant to continue former work on the project conventienly. TwinCAT 3 Engineering stores such settings in files which are called &amp;#34;Solution User Options (.suo) File&amp;#34;. When such settings are manipulated or crafted by an adversary in a specific way then TwinCAT 3 Engineering executes arbitrary commands as determined by these settings when the user uses TwinCAT 3 Engineering to open the project. These arbitrary commands are executed in the user context.&lt;/p&gt;
&lt;p&gt;Please note that solution user option files should not be checked in to source code control. This is also a best practice when working with source code projects and solutions. For example, see https://learn.microsoft.com/en-us/visualstudio/extensibility/internals/solution-user-options-dot-suo-file and https://infosys.beckhoff.com/content/1033/tc3_sourcecontrol/14604066827.html.&lt;/p&gt;
&lt;p&gt;The vulnerability is similar to older vulnerabilities that were addressed in the CODESYS Development System V3 product from CODESYS GmbH with CVE-2021-21864, CVE-2021-21865, CVE-2021-21866, CVE-2021-21867, CVE-2021-21868, CVE-2021-21869, and the associated Advisory 2021-13 from CODESYS GmbH.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Beckhoff&amp;#39;s TwinCAT 3 Engineering software is intented to craft automation projects consisting of a set of files which are stored locally as files underneath an individual folder or in a packed file. The TwinCAT 3 Engineering stores user settings and preferences among the non packed local files which are relevant to continue former work on the project conventienly. TwinCAT 3 Engineering stores such settings in files which are called &amp;#34;Solution User Options (.suo) File&amp;#34;. When such settings are manipulated or crafted by an adversary in a specific way then TwinCAT 3 Engineering executes arbitrary commands as determined by these settings when the user uses TwinCAT 3 Engineering to open the project. These arbitrary commands are executed in the user context.&lt;/p&gt;
&lt;p&gt;Please note that solution user option files should not be checked in to source code control. This is also a best practice when working with source code projects and solutions. For example, see https://learn.microsoft.com/en-us/visualstudio/extensibility/internals/solution-user-options-dot-suo-file and https://infosys.beckhoff.com/content/1033/tc3_sourcecontrol/14604066827.html.&lt;/p&gt;
&lt;p&gt;The vulnerability is similar to older vulnerabilities that were addressed in the CODESYS Development System V3 product from CODESYS GmbH with CVE-2021-21864, CVE-2021-21865, CVE-2021-21866, CVE-2021-21867, CVE-2021-21868, CVE-2021-21869, and the associated Advisory 2021-13 from CODESYS GmbH.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-075</guid>
      <pubDate>Tue, 09 Sep 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-003 — BECKHOFF: Null Pointer Dereference vulnerability in products with OPC UA technology</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-003</link>
      <description>&lt;p&gt;By tricking clients of the mentioned products into contacting malicious OPC UA servers and thereby acting as OPC UA clients, a crash of the component can be provoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;By tricking clients of the mentioned products into contacting malicious OPC UA servers and thereby acting as OPC UA clients, a crash of the component can be provoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-003</guid>
      <pubDate>Tue, 01 Mar 2022 12:34:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-050 — Beckhoff: Denial-of-Service vulnerability in the MDP package included in TwinCAT/BSD operating system</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-050</link>
      <description>&lt;p&gt;The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local
attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in
the context of user &amp;#39;root&amp;#39; via a crafted HTTP request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local
attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in
the context of user &amp;#39;root&amp;#39; via a crafted HTTP request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-050</guid>
      <pubDate>Tue, 27 Aug 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-049 — Beckhoff: Denial-of-Service vulnerability in the IPC-Diagnostics package included in TwinCAT/BSD operating system</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-049</link>
      <description>&lt;p&gt;The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-049</guid>
      <pubDate>Tue, 27 Aug 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-048 — Beckhoff: Improper neutralization of input in IPC-Diagnostics-www package included in TwinCAT/BSD operating system</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-048</link>
      <description>&lt;p&gt;The IPC-Diagnostics-www package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The IPC-Diagnostics-www package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-048</guid>
      <pubDate>Tue, 27 Aug 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-045 — Beckhoff: Local authentication bypass in IPC-Diagnostics package included in TwinCAT/BSD operating system</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-045</link>
      <description>&lt;p&gt;The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-045</guid>
      <pubDate>Tue, 27 Aug 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-067 — Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhf</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-067</link>
      <description>&lt;p&gt;The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-067</guid>
      <pubDate>Wed, 13 Dec 2023 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-051 — Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-051</link>
      <description>&lt;p&gt;TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-051</guid>
      <pubDate>Thu, 04 Nov 2021 07:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
