Vulnerabilities > BR Automation
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-14 | CVE-2023-1617 | Improper Authentication vulnerability in Br-Automation VC4 Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. | 9.8 |
2023-02-14 | CVE-2022-4286 | Cross-site Scripting vulnerability in Br-Automation Automation Runtime A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session. | 6.1 |
2023-02-08 | CVE-2022-43762 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Br-Automation Industrial Automation Aprol Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages | 9.8 |
2023-02-08 | CVE-2022-43763 | Unchecked Return Value vulnerability in Br-Automation Industrial Automation Aprol Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07. | 7.5 |
2023-02-08 | CVE-2022-43764 | Out-of-bounds Write vulnerability in Br-Automation Industrial Automation Aprol Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. | 9.8 |
2023-02-08 | CVE-2022-43765 | Unchecked Return Value vulnerability in Br-Automation Industrial Automation Aprol B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service. | 7.5 |
2023-02-08 | CVE-2022-43761 | Missing Authentication for Critical Function vulnerability in Br-Automation Industrial Automation Aprol Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. | 7.5 |
2022-08-11 | CVE-2021-22289 | Improper Input Validation vulnerability in Br-Automation Studio Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code. | 9.8 |
2022-05-13 | CVE-2021-22275 | Classic Buffer Overflow vulnerability in Br-Automation Automation Runtime Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service. | 8.6 |
2020-11-27 | CVE-2019-19878 | Unspecified vulnerability in Br-Automation Industrial Automation Aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. | 7.5 |