CVE-2024-8934: Beckhoff Twincat Package Manager

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.

Affected products

  • Beckhoff Twincat Package Manager: before 1.0.603.0 (fixed in 1.0.603.0)
  • Beckhoff Twincat Packet Manager: before 1.0.603.0 (fixed in 1.0.603.0)

Published 2024-10-31. Last modified 2026-06-17.