CVE-2025-41728: Beckhoff: Information leak via Beckhoff Device Manager
A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41728?
The severity of CVE-2025-41728 is considered to be low due to the requirement of low privileged access for exploitation.
How do I fix CVE-2025-41728?
To fix CVE-2025-41728, ensure you update the Beckhoff Device Manager to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-41728?
CVE-2025-41728 affects users of the Beckhoff Device Manager running an unpatched version.
What type of vulnerability is CVE-2025-41728?
CVE-2025-41728 is classified as an information leak vulnerability resulting from an out-of-bounds read operation.
Can CVE-2025-41728 be exploited remotely?
Yes, CVE-2025-41728 can be exploited remotely by sending specially crafted calls to the Device Manager web service.