Known Vulnerabilities for products from Beckhoff

Listed below are 16 of the newest known vulnerabilities associated with the vendor "Beckhoff".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Beckhoff can be found at device.report : Beckhoff

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-34594 json TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194... 6.5 - MEDIUM 2021-11-04 2021-11-06
CVE-2020-20741 json Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B... 9.8 - CRITICAL 2021-07-23 2021-08-09
CVE-2020-12526 json TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automa... 5.3 - MEDIUM 2021-05-13 2021-05-25
CVE-2020-12510 json The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does... 7.3 - HIGH 2020-11-19 2020-12-03
CVE-2020-12494 json Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements rea... 5.3 - MEDIUM 2020-06-16 2021-12-02
CVE-2020-9464 json A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the de... 7.5 - HIGH 2020-03-12 2020-03-16
CVE-2019-16871 json Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to... 9.8 - CRITICAL 2019-12-19 2021-07-21
CVE-2019-5637 json When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sen... 7.5 - HIGH 2019-11-21 2020-02-04
CVE-2019-5636 json When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT ... 7.5 - HIGH 2019-11-21 2020-02-04
CVE-2018-7502 json Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-sup... 7.8 - HIGH 2018-03-23 2018-05-23
CVE-2017-16726 json Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS ... 9.1 - CRITICAL 2018-06-27 2019-10-09
CVE-2017-16718 json Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. Th... 5.9 - MEDIUM 2018-06-27 2019-10-09
CVE-2015-4051 json Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers ... Not Provided 2015-06-08 2026-05-06
CVE-2014-5415 json Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote... Not Provided 2016-10-05 2026-05-06
CVE-2014-5414 json Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict th... Not Provided 2016-10-05 2026-05-06
CVE-2011-3486 json Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP po... Not Provided 2011-09-16 2026-04-29

Known software with vulnerabilities from Beckhoff

Type Vendor Product Version
HardwareBeckhoffBk9000-
Operating
System
BeckhoffBk9000 Firmware-
ApplicationBeckhoffTwincat2.0
Operating
System
BeckhoffTwincat3.1.4022.29
HardwareBeckhoffTwincat Cx2030-
HardwareBeckhoffTwincat Cx5140-
ApplicationBeckhoffTwincat Extended Automation Runtime3.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report