{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "tracking": {
            "generator": {
                "date": "2025-03-12T10:03:53.568Z",
                "engine": {
                    "version": "2.5.18",
                    "name": "Secvisogram"
                }
            },
            "id": "VDE-2021-051",
            "version": "2",
            "status": "final",
            "aliases": [
                "VDE-2021-051"
            ],
            "revision_history": [
                {
                    "number": "1",
                    "summary": "initial revision",
                    "date": "2021-11-04T07:00:00.000Z"
                },
                {
                    "number": "2",
                    "summary": "Fix: added distribution, quotation mark",
                    "date": "2025-05-22T13:03:10.000Z"
                }
            ],
            "current_release_date": "2025-05-22T13:03:10.000Z",
            "initial_release_date": "2021-11-04T07:00:00.000Z"
        },
        "lang": "en-GB",
        "title": "Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server",
        "acknowledgments": [
            {
                "organization": "CERTVDE",
                "urls": [
                    "https://certvde.com"
                ],
                "summary": "coordination"
            }
        ],
        "distribution": {
            "tlp": {
                "label": "WHITE",
                "url": "https://www.first.org/tlp/"
            }
        },
        "notes": [
            {
                "category": "summary",
                "title": "Summary",
                "text": "Through specific nodes of the server configuration interface of the TwinCAT OPC UA Server administrators are able to remotely create and delete any files on the system which the server is running on, though this access should have been restricted to specific directories. In case that configuration interface is combined with not recommended settings to allow anonymous access via the TwinCAT OPC UA Server then this kind of file access is even possible for any unauthenticated user from remote."
            },
            {
                "category": "description",
                "title": "Impact",
                "text": "The OPC UA server called 'TcOpcUaServer' provides specific nodes within a specifc namespace which allow to configure features of that OPC UA server. By accessing some of these nodes an OPC UA client can create and delete configuration files for these features on behalf of the administrator of the 'TcOpcUaServer'. For these files dedicated directories are used on the file system of the computer where the 'TcOpcUaServer' is running. Affected versions were missing specific sanity checks for the file names used and an attacker could add relative paths to the file names to create and delete files outside of the dedicated directories.\n\nThe specific nodes reside within the OPC UA namespace which is identified by the following namespace URI:\n\nhttp://beckhoff.com/TwinCAT/TF6100/Server/Configuration\nWith the default configuration the dedicated directories are the following on the system partition of the system where 'TcOpcUAServer' is running:\n\nTwinCAT\\Functions\\TF6100-OPC-UA\\Server\\res\nTwinCAT\\Functions\\TF6100-OPC-UA\\Server\\xmlnodesets\nTwinCAT\\Functions\\TF6100-OPC-UA\\Server\\symbolfiles\nPlease note that the default installation of the 'TcOpcUAServer' does allow anonymous access even to the administrative nodes within the namespace described above. However, Beckhoff recommends to restrict access with the help of the various security features of the 'TcOpcUaServer' as described with \"Configuring security settings - Beckhoff Information System external link\" . This is why operating the 'TcOpcUAServer' with allowing anonymous access to the administrative nodes is not considered the intended use here."
            },
            {
                "category": "description",
                "title": "Mitigation",
                "text": "Consider restricting access to the nodes of the 'TcOpcUAServer' with the methods described by https://infosys.beckhoff.com/content/1033/tcopcuaserver/5930038411-1.html such that the administrative interface can only be accessed by administrative users of well known OPC UA clients."
            },
            {
                "category": "description",
                "title": "Remediation",
                "text": "Please update to a recent version of the affected product."
            }
        ],
        "publisher": {
            "category": "vendor",
            "contact_details": "product-securityincident@beckhoff.com",
            "name": "Beckhoff Automation GmbH & Co. KG",
            "namespace": "https://www.beckhoff.com"
        },
        "references": [
            {
                "category": "external",
                "summary": "Beckhoff Automation GmbH & Co. KG",
                "url": "https://infosys.beckhoff.com/index.php?content=../content/1031/ipc_security/976057355.html&id="
            },
            {
                "category": "external",
                "summary": "CERT@VDE Security Advisories",
                "url": "https://certvde.com/en/advisories/vendor/Beckhoff/"
            },
            {
                "category": "self",
                "url": "https://certvde.com/en/advisories/VDE-2021-051/",
                "summary": "VDE-2021-051: Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server - HTML"
            },
            {
                "summary": "VDE-2021-051: Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server - CSAF",
                "url": "https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-051.json",
                "category": "self"
            }
        ]
    },
    "product_tree": {
        "branches": [
            {
                "category": "vendor",
                "name": "Beckhoff Automation GmbH & Co. KG",
                "branches": [
                    {
                        "category": "product_family",
                        "name": "Hardware",
                        "branches": [
                            {
                                "category": "product_name",
                                "name": "TwinCAT OPC UA Server in TF6100 < 4.3.48.0",
                                "product": {
                                    "name": "TwinCAT OPC UA Server in TF6100 < 4.3.48.0",
                                    "product_id": "CSAFPID-11001"
                                }
                            },
                            {
                                "category": "product_name",
                                "name": "TwinCAT OPC UA Server in TS6100 < 4.3.48.0",
                                "product": {
                                    "name": "TwinCAT OPC UA Server in TS6100 < 4.3.48.0",
                                    "product_id": "CSAFPID-11002"
                                }
                            }
                        ]
                    },
                    {
                        "category": "product_family",
                        "name": "Firmware",
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "<3.2.0.194",
                                "product": {
                                    "name": "Firmware <3.2.0.194",
                                    "product_id": "CSAFPID-21001"
                                }
                            },
                            {
                                "category": "product_version",
                                "name": "3.2.0.194",
                                "product": {
                                    "name": "Firmware 3.2.0.194",
                                    "product_id": "CSAFPID-22001"
                                }
                            }
                        ]
                    }
                ]
            }
        ],
        "relationships": [
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-21001",
                "relates_to_product_reference": "CSAFPID-11001",
                "full_product_name": {
                    "name": "Firmware <3.2.0.194 installed on TwinCAT OPC UA Server in TF6100 < 4.3.48.0",
                    "product_id": "CSAFPID-31001"
                }
            },
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-22001",
                "relates_to_product_reference": "CSAFPID-11001",
                "full_product_name": {
                    "name": "Firmware 3.2.0.194 installed on TwinCAT OPC UA Server in TF6100 < 4.3.48.0",
                    "product_id": "CSAFPID-32001"
                }
            },
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-21001",
                "relates_to_product_reference": "CSAFPID-11002",
                "full_product_name": {
                    "name": "Firmware <3.2.0.194 installed on TwinCAT OPC UA Server in TS6100 < 4.3.48.0",
                    "product_id": "CSAFPID-31002"
                }
            },
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-22001",
                "relates_to_product_reference": "CSAFPID-11002",
                "full_product_name": {
                    "name": "Firmware 3.2.0.194 installed on TwinCAT OPC UA Server in TS6100 < 4.3.48.0",
                    "product_id": "CSAFPID-32002"
                }
            }
        ],
        "product_groups": [
            {
                "group_id": "CSAFGID-0001",
                "summary": "affected products",
                "product_ids": [
                    "CSAFPID-31001",
                    "CSAFPID-31002"
                ]
            },
            {
                "group_id": "CSAFGID-0002",
                "summary": "fixed products",
                "product_ids": [
                    "CSAFPID-32001",
                    "CSAFPID-32002"
                ]
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2021-34594",
            "product_status": {
                "known_affected": [
                    "CSAFPID-31001",
                    "CSAFPID-31002"
                ],
                "fixed": [
                    "CSAFPID-32001",
                    "CSAFPID-32002"
                ]
            },
            "scores": [
                {
                    "cvss_v3": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "HIGH",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "temporalScore": 6.5,
                        "temporalSeverity": "MEDIUM",
                        "environmentalScore": 6.5,
                        "environmentalSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-31001",
                        "CSAFPID-31002"
                    ]
                }
            ],
            "notes": [
                {
                    "category": "summary",
                    "text": "TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system."
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "Consider restricting access to the nodes of the 'TcOpcUAServer' with the methods described by https://infosys.beckhoff.com/content/1033/tcopcuaserver/5930038411-1.html such that the administrative interface can only be accessed by administrative users of well known OPC UA clients.",
                    "group_ids": [
                        "CSAFGID-0001"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Please update to a recent version of the affected product.",
                    "group_ids": [
                        "CSAFGID-0001"
                    ]
                }
            ],
            "title": "CVE-2021-34594",
            "cwe": {
                "id": "CWE-23",
                "name": "Relative Path Traversal"
            }
        }
    ]
}