AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Beckhoff
BE
Platform

Beckhoff

Pioneer of PC-based control technology. Products include CX Embedded PCs, AX5000 servo drives, EtherCAT I/O modules, and TwinCAT 3 software PLC.

https://www.beckhoff.com/ →
16
Total CVEs
10
Resources
5
CRIT
5
HIGH
6
MED
0
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
6 / 16
CVE-2017-16718MEDIUM

Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.

Jun 27, 2018
5.9
CVE-2020-12526MEDIUM

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.

May 13, 2021
5.3
CVE-2020-12494MEDIUM

Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device.

Jun 16, 2020
5.3
CVE-2019-5636MEDIUM

When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).

Nov 21, 2019
5.3
CVE-2011-3486MEDIUM

Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.

Sep 16, 2011
5.0
CVE-2023-6545MEDIUM

The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.

Dec 14, 2023
4.7
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2017-16718MEDIUM
5.9
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in p…Jun 27, 2018›
CVE-2020-12526MEDIUM
5.3
TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1…May 13, 2021›
CVE-2020-12494MEDIUM
5.3
Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. …Jun 16, 2020›
CVE-2019-5636MEDIUM
5.3
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts dow…Nov 21, 2019›
CVE-2011-3486MEDIUM
5.0
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a …Sep 16, 2011›
CVE-2023-6545MEDIUM
4.7
The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows …Dec 14, 2023›