TwinCAT/BSD Vulnerability Allows DoS and Root Execution via Crafted HTTP Request
CVE-2024-41176

7.3HIGH

Key Information:

Vendor

Beckhoff

Vendor
CVE Published:
27 August 2024

What is CVE-2024-41176?

The MPD package within TwinCAT/BSD presents a vulnerability that allows authenticated, low-privileged local attackers to exploit the system. By sending a specially crafted HTTP request, the attacker can disrupt the service provided by the daemon, leading to a Denial-of-Service (DoS) condition. Moreover, this exploit can enable the attacker to execute arbitrary code in the context of the user 'root', raising significant security concerns for affected systems.

Affected Version(s)

MDP package 0 < 1.2.7.0

TwinCAT/BSD 0 < 14.1.2.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nozomi Networks
Andrea Palanca
.