No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49492 | A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed. |
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2024-064 |
|
Thu, 31 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Beckhoff
Beckhoff twincat Packet Manager |
|
| CPEs | cpe:2.3:a:beckhoff:twincat_packet_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Beckhoff
Beckhoff twincat Packet Manager |
|
| Metrics |
ssvc
|
Thu, 31 Oct 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed. | |
| Title | Beckhoff: Local command injection via TwinCAT Package Manager | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-10-31T13:47:50.093Z
Reserved: 2024-09-17T07:33:02.586Z
Link: CVE-2024-8934
Updated: 2024-10-31T13:47:38.965Z
Status : Deferred
Published: 2024-10-31T13:15:15.040
Modified: 2026-06-17T08:23:35.133
Link: CVE-2024-8934
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
EUVD