CVE-2015-4051

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
08/06/2015
Last modified:
12/04/2025

Description

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:beckhoff:ipc_diagnostics:*:*:*:*:*:*:*:* 1.7 (including)