A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.
History

Tue, 27 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Beckhoff
Beckhoff beckhoff.device.manager.xar
Beckhoff mdp Package
Beckhoff twincat
Beckhoff twincat/bsd
Vendors & Products Beckhoff
Beckhoff beckhoff.device.manager.xar
Beckhoff mdp Package
Beckhoff twincat
Beckhoff twincat/bsd

Tue, 27 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 11:45:00 +0000

Type Values Removed Values Added
Description A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.
Title Beckhoff: Performing privileged operations and gaining administrator access
Weaknesses CWE-420
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-01-27T13:53:55.876Z

Reserved: 2025-04-16T11:17:48.318Z

Link: CVE-2025-41727

cve-icon Vulnrichment

Updated: 2026-01-27T13:53:51.885Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-27T12:15:57.573

Modified: 2026-01-27T14:59:34.073

Link: CVE-2025-41727

cve-icon Redhat

No data.