CVE-2021-34594
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
04/11/2021
Last modified:
06/11/2021
Description
TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:beckhoff:tf6100_firmware:*:*:*:*:*:*:*:* | 4.3.48.0 (excluding) | |
| cpe:2.3:h:beckhoff:tf6100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:beckhoff:ts6100_firmware:*:*:*:*:*:*:*:* | 4.3.48.0 (excluding) | |
| cpe:2.3:h:beckhoff:ts6100:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



