← Back

CVE-2023-1617

nvd nist
Published: Apr 14, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this vulnerability depends on the functionality provided in the visualization. This issue affects B&R VC4: from 3.* through 3.96.7, from 4.0* through 4.06.7, from 4.1* through 4.16.3, from 4.2* through 4.26.8, from 4.3* through 4.34.6, from 4.4* through 4.45.1, from 4.5* through 4.45.3, from 4.7* through 4.72.9.

Affected (8)

Products: Br Automation: Vc4
1 product
Vc4
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Br Automation
Before 3.96.8
From 4.0.0 to 4.06.4
From 4.10.0 to 4.16.3
From 4.20.0 to 4.26.8
From 4.30.0 to 4.34.7
From 4.40.0 to 4.45.1
From 4.50.0 to 4.53.0
From 4.70.0 to 4.73.0

Timeline

No history available yet.