Showing 3 vulnerabilities on this page for MDP software package for TwinCAT/BSD

Signals CISA KEV Ransomware Nuclei
Beckhoff Automation vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Beckhoff: Information leak via Beckhoff Device Manager

A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.

CWE-125Jan 27, 2026
CVSS5.3v3.1EPSS0.309%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Beckhoff: Performing privileged operations and gaining administrator access

A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.

CWE-420Jan 27, 2026
CVSS7.8v3.1EPSS0.163%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Beckhoff: Arbitrary code execution within privileged processes

A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes.

CWE-190Jan 27, 2026
CVSS8.8v3.1EPSS0.414%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX