CVE-2018-7502: Beckhoff Twincat

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.

Affected products

  • Beckhoff Twincat: version 2.11 only; version 3.1 only
  • Beckhoff Twincat C++: version 3.1 only

Published 2018-03-23. Last modified 2026-06-17.