Br Automation
br-automation
41 CVEs • 14 products
Products (14)
Click to collapseToggle
Products (14)
Click to collapse
CVEs (41)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Br Automation 1Industrial Automation Aprol Sep 13, 2024 Aug 29, 2024 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session |
1Br Automation 1Industrial Automation Aprol Sep 13, 2024 Aug 29, 2024 5.4 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges. |
1Br Automation 1Industrial Automation Aprol Sep 13, 2024 Aug 29, 2024 7.3 HIGH· v4 7.8 HIGH· v3 N/A· v2 An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges. |
1Br Automation 1Automation Runtime Dec 19, 2025 Aug 12, 2024 8.3 HIGH· v4 7.5 HIGH· v3 N/A· v2 Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication. |
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product. |
1Br Automation 2Automation Studio Technology GuardingMay 6, 2025 Feb 22, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to exec...Show more |
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code...Show more |
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to dec...Show more |
: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.
|
1Br Automation 2Automation Net/pvi Automation StudioNov 21, 2024 Feb 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4...Show more |
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.
|
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 be...Show more |
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions. |
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 v...Show more |
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the conte...Show more |
1Br Automation 1Industrial Automation Aprol Nov 21, 2024 Feb 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 B&R APROL versions < R 4.2-07 doesn’t process correctly specially
formatted data packages sent to port 55502/tcp, which may allow a network based
attacker to cause an application Denial-of-Service.
|
1Br Automation 1Industrial Automation Aprol Nov 21, 2024 Feb 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbi...Show more |
1Br Automation 1Industrial Automation Aprol Nov 21, 2024 Feb 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient check of preconditions could lead
to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.
|
1Br Automation 1Industrial Automation Aprol Nov 21, 2024 Feb 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Lack of verification in B&R APROL
Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages
|
1Br Automation 1Industrial Automation Aprol Nov 21, 2024 Feb 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Missing authentication when creating and
managing the B&R APROL database in versions < R 4.2-07
allows reading and changing the system configuration.
|