CVE-2014-5415
9.1
CRITICAL · CVSS 3.1 · EPSS 4.3% (pctl 91)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Display service, or (3) TELNET service.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 4.34% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-749 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-10-05 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| beckhoff | embedded pc images |
| beckhoff | twincat |
References
- http://www.securityfocus.com/bid/93349
- https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2014-001.pdf
- https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2014-002.pdf
- https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2014-003.pdf
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2016/icsa-16-278-02.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-16-278-02
- http://www.securityfocus.com/bid/93349
- https://ics-cert.us-cert.gov/advisories/ICSA-16-278-02
→ the Explorer · watch your stack · NVD