CVE-2024-41176

The MPD package included in TwinCAT/BSDallows an authenticated, low-privileged local
attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in
the context of user root via a crafted HTTP request.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CERTVDECNA
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
beckhofftwincat\/bsd
𝑥
< 14.1.2.0
beckhoffmdp_package
𝑥
< 1.2.7.0
beckhoffmdp_package
𝑥
< 1.2.7.0
beckhofftwincat\/bsd
𝑥
< 14.1.2.0
𝑥
= Vulnerable software versions