CVE-2024-41176: Beckhoff Mdp Package
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.
Affected products
- Beckhoff Mdp Package: before 1.2.7.0 (fixed in 1.2.7.0)
- Beckhoff Twincat/bsd: before 14.1.2.0 (fixed in 14.1.2.0)
Published 2024-08-27. Last modified 2026-06-17.