SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34594

TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.

MEDIUM 6.5EPSS 1.13%

Does this matter?

Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.

Description

TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS
1.13% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-23, CWE-22
Affected
beckhoff/tf6100 firmware · beckhoff/ts6100 firmware
Source
info@cert.vde.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.