Twincat

Vendor:

First CVE: Sep 16, 2011 · Active for 14 years

10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Twincat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2011
14 years ago
Most Recent CVE
Jun 16, 2020
2,231 days ago

CVE Severity & Scoring

Twincat10 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network8 (80.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High1 (10.0%)
Unknown1 (10.0%)
User Interaction
None9 (90.0%)
Unknown1 (10.0%)
Required0 (0.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None8 (80.0%)
Unknown1 (10.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.
Sep 16, 20115.061NOYES
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beck
Dec 19, 20199.831NONO
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remo
Oct 5, 20169.130NONO
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it eas
Oct 5, 20169.130NONO
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and
Jun 27, 20189.128NONO
When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue a
Nov 21, 20197.523NONO
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affe
Nov 21, 20197.523NONO
Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execut
Mar 23, 20187.823NONO
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be ed
Jun 27, 20185.921NONO
Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from r
Jun 16, 20205.320NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
10.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Twincat

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.1.4022.3017.51.4%00
3.1.4022.2917.51.4%00
3.138.73.1%00
3.015.90.4%00
2.915.050.6%01
2.815.050.6%01
2.715.050.6%01
2.1117.80.6%00
2.1015.050.6%01
2.028.73.4%00