VendorsBeckhofftwincatany version
Vulnerabilities

Beckhoff TwinCAT any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2019-16871
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
Published 2019-12-19 · Modified
9.8EPSS 0.053
CVE-2014-5414
Beckhoff Embedded PC Images and TwinCAT Components Improper Restriction of Excessive Authentication Attempts
Published 2016-10-05 · Modified
9.4EPSS 0.048
CVE-2014-5415
Beckhoff Embedded PC Images and TwinCAT Components Exposed Dangerous Method or Function
Published 2016-10-05 · Modified
9.4EPSS 0.043
CVE-2017-16726
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on performance and throughput. An attacker can forge arbitrary ADS packets when legitimate ADS traffic is observable.
Published 2018-06-27 · Modified
9.1EPSS 0.005
CVE-2020-12494
Beckhoff: Etherleak in TwinCAT RT network driver
Published 2020-06-16 · Modified
5.3EPSS 0.010
CVE-2011-3486
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.
Published 2011-09-16 · Modified
5.01 PoCEPSS 0.497