Beckhoff develops a focused line of industrial automation and embedded control products, with TwinCAT runtime environments and industrial PCs sitting at the core of programmable logic and real-time systems deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the consequence of memory-safety and resource-management gaps in embedded and real-time software. The recurring weakness classes center on input validation, resource exhaustion, and authentication bypass mechanisms—patterns endemic to protocol-handling and privileged-access control in automation platforms—and surface across the TwinCAT product family and associated embedded PC images. Defenders managing industrial environments should prioritize Beckhoff advisories within their automation infrastructure and monitor the vendor's update cycles; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beckhoff over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3486MEDIUM Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read. | Sep 16, 2011 | 5.0 | 61 | NO | YES |
CVE-2020-20741CRITICAL Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication | Jul 23, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-16871CRITICAL Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beck | Dec 19, 2019 | 9.8 | 31 | NO | NO |
CVE-2014-5415CRITICAL Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remo | Oct 5, 2016 | 9.1 | 30 | NO | NO |
CVE-2014-5414CRITICAL Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it eas | Oct 5, 2016 | 9.1 | 30 | NO | NO |
CVE-2017-16726CRITICAL Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and | Jun 27, 2018 | 9.1 | 28 | NO | NO |
CVE-2020-9464HIGH A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting. | Mar 12, 2020 | 7.5 | 24 | NO | NO |
CVE-2015-4051HIGH Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), crea | Jun 8, 2015 | 9.0 | 24 | NO | NO |
CVE-2024-41173HIGH The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker. | Aug 27, 2024 | 7.8 | 23 | NO | NO |
CVE-2020-12510HIGH The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created wi | Nov 19, 2020 | 7.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beckhoff.
Media articles that mention a CVE ID that affects a product developed by Beckhoff — matched by CVE ID, not by vendor name.