← back
CVE-2024-8934

Beckhoff: Local command injection via TwinCAT Package Manager

CVSS 6.5 MEDIUMEPSS 0.2%CWE-78
A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →