← Back

Br Automation

br-automation

41 CVEs • 14 products

Products (14)

Click to collapse
Toggle

CVEs (41)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Br Automation
1Industrial Automation Aprol
Sep 13, 2024
Aug 29, 2024
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session
1Br Automation
1Industrial Automation Aprol
Sep 13, 2024
Aug 29, 2024
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.
1Br Automation
1Industrial Automation Aprol
Sep 13, 2024
Aug 29, 2024
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.
1Br Automation
1Automation Runtime
Dec 19, 2025
Aug 12, 2024
8.3 HIGH· v4
7.5 HIGH· v3
N/A· v2
Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.
1Br Automation
1Automation Studio
Dec 19, 2025
May 14, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.
1Br Automation
2Automation Studio
Technology Guarding
May 6, 2025
Feb 22, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to exec...Show more
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.Show less
1Br Automation
1Automation Runtime
Nov 21, 2024
Feb 5, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code...Show more
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session. Show less
1Br Automation
1Automation Runtime
Nov 21, 2024
Feb 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to dec...Show more
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.Show less
1Br Automation
1Automation Studio
Nov 21, 2024
Feb 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.
1Br Automation
2Automation Net/pvi
Automation Studio
Nov 21, 2024
Feb 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4...Show more
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP; NET/PVI: from 4.0 through 4.6, from 4.7.0 before 4.7.7, from 4.8.0 before 4.8.6, from 4.9.0 before 4.9.4. Show less
1Br Automation
1Automation Studio
Nov 21, 2024
Feb 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.
1Br Automation
1Automation Studio
Nov 21, 2024
Feb 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 be...Show more
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP. Show less
1Br Automation
1Automation Runtime
Nov 21, 2024
Jul 26, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
1Br Automation
1Vc4
Nov 21, 2024
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 v...Show more
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this vulnerability depends on the functionality provided in the visualization. This issue affects B&R VC4: from 3.* through 3.96.7, from 4.0* through 4.06.7, from 4.1* through 4.16.3, from 4.2* through 4.26.8, from 4.3* through 4.34.6, from 4.4* through 4.45.1, from 4.5* through 4.45.3, from 4.7* through 4.72.9. Show less
1Br Automation
1Automation Runtime
Nov 21, 2024
Feb 14, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the conte...Show more
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session. Show less
1Br Automation
1Industrial Automation Aprol
Nov 21, 2024
Feb 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.
1Br Automation
1Industrial Automation Aprol
Nov 21, 2024
Feb 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbi...Show more
Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code. Show less
1Br Automation
1Industrial Automation Aprol
Nov 21, 2024
Feb 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.
1Br Automation
1Industrial Automation Aprol
Nov 21, 2024
Feb 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
 Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages
1Br Automation
1Industrial Automation Aprol
Nov 21, 2024
Feb 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration.