CVE-2021-34594: Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server

Published Nov 4, 2021
·
Updated

TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.

Affected Software

4 affected components
Beckhoff Tf6100 Firmware<4.3.48.0
Beckhoff TF6100
Beckhoff Ts6100 Firmware<4.3.48.0
Beckhoff TS6100

Remediation

Information

Please update to a recent version of the affected product (TF6100 or TS6100 version >= 4.3.48.0)

Event History

Nov 4, 2021
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2021-34594?

CVE-2021-34594 has a high severity rating due to the potential for unauthorized file creation and deletion on the system.

2

How do I fix CVE-2021-34594?

To fix CVE-2021-34594, upgrade TwinCAT OPC UA Server to version 4.3.48.0 or later, or TcOpcUaServer to version 3.2.0.194 or later.

3

Which products are affected by CVE-2021-34594?

CVE-2021-34594 affects the TwinCAT OPC UA Server in TF6100 and TS6100 product versions before 4.3.48.0.

4

What type of vulnerability is CVE-2021-34594?

CVE-2021-34594 is a relative path traversal vulnerability that allows file manipulation on the affected systems.

5

Who is the vendor for CVE-2021-34594?

The vendor for CVE-2021-34594 is Beckhoff, which develops the TF6100 and TS6100 product lines.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203