CVE Vulnerabilities

CVE-2024-41173

Authentication Bypass Using an Alternate Path or Channel

Published: Aug 27, 2024 | Modified: Sep 12, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Ipc_diagnostics_package Beckhoff * 2.0.0.1 (excluding)
Twincat/bsd Beckhoff * 14.1.2.0 (excluding)

Potential Mitigations

References