VendorsBeckhofftwincatall versions
Vulnerabilities

Beckhoff TwinCAT

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2019-16871
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
Published 2019-12-19 · Modified
9.8EPSS 0.053
CVE-2014-5414
Beckhoff Embedded PC Images and TwinCAT Components Improper Restriction of Excessive Authentication Attempts
Published 2016-10-05 · Modified
9.4EPSS 0.048
CVE-2014-5415
Beckhoff Embedded PC Images and TwinCAT Components Exposed Dangerous Method or Function
Published 2016-10-05 · Modified
9.4EPSS 0.043
CVE-2017-16726
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on performance and throughput. An attacker can forge arbitrary ADS packets when legitimate ADS traffic is observable.
Published 2018-06-27 · Modified
9.1EPSS 0.005
CVE-2018-7502
Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.
Published 2018-03-23 · Modified
7.8EPSS 0.006
CVE-2019-5636
Beckhoff TwinCAT Discovery Service Denial of Service
Published 2019-11-21 · Modified
7.5EPSS 0.014
CVE-2019-5637
Beckhoff TwinCAT Profinet Driver Divide-by-Zero Denial of Service
Published 2019-11-21 · Modified
7.5EPSS 0.014
CVE-2017-16718
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.
Published 2018-06-27 · Modified
5.9EPSS 0.004
CVE-2020-12494
Beckhoff: Etherleak in TwinCAT RT network driver
Published 2020-06-16 · Modified
5.3EPSS 0.010
CVE-2011-3486
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.
Published 2011-09-16 · Modified
5.01 PoCEPSS 0.497