Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Beckhoff

First CVE: Sep 16, 2011Active for: 15 yearsTotal CVEs: 21
39.0
VTI Score
Medium

Beckhoff develops a focused line of industrial automation and embedded control products, with TwinCAT runtime environments and industrial PCs sitting at the core of programmable logic and real-time systems deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the consequence of memory-safety and resource-management gaps in embedded and real-time software. The recurring weakness classes center on input validation, resource exhaustion, and authentication bypass mechanisms—patterns endemic to protocol-handling and privileged-access control in automation platforms—and surface across the TwinCAT product family and associated embedded PC images. Defenders managing industrial environments should prioritize Beckhoff advisories within their automation infrastructure and monitor the vendor's update cycles; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Beckhoff over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2011
14 years ago
Most Recent CVE
Aug 27, 2024
696 days ago

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-3486MEDIUM
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.
Sep 16, 20115.061NOYES
CVE-2020-20741CRITICAL
Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication
Jul 23, 20219.831NONO
CVE-2019-16871CRITICAL
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beck
Dec 19, 20199.831NONO
CVE-2014-5415CRITICAL
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remo
Oct 5, 20169.130NONO
CVE-2014-5414CRITICAL
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it eas
Oct 5, 20169.130NONO
CVE-2017-16726CRITICAL
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and
Jun 27, 20189.128NONO
CVE-2020-9464HIGH
A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.
Mar 12, 20207.524NONO
CVE-2015-4051HIGH
Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), crea
Jun 8, 20159.024NONO
CVE-2024-41173HIGH
The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.
Aug 27, 20247.823NONO
CVE-2020-12510HIGH
The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created wi
Nov 19, 20207.323NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
33%
43%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (28.6%)
Network13 (61.9%)
Unknown2 (9.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (85.7%)
High1 (4.8%)
Unknown2 (9.5%)
User Interaction
None16 (76.2%)
Unknown2 (9.5%)
Required3 (14.3%)
Privileges Required
Low6 (28.6%)
High1 (4.8%)
None12 (57.1%)
Unknown2 (9.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Beckhoff.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Beckhoff — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Beckhoff's Products

View all 4 CNAs →

Top CWEs