5.5

CVE-2024-41175

Beckhoff: Local Denial-of-Service vulnerability in TwinCAT/BSD and the IPC-Diagnostics package

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BeckhoffIpc Diagnostics Package Version < 2.0.0.1
BeckhoffTwincat/bsd Version < 14.1.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://cert.vde.com/en/advisories/VDE-2024-049/
Third Party Advisory
Mitigation
https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614
Vendor Advisory