Vulnerabilities > BR Automation > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-05 | CVE-2024-0323 | Use of a Risky Cryptographic Primitive vulnerability in Br-Automation Automation Runtime The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. | 9.8 |
2023-04-14 | CVE-2023-1617 | Improper Authentication vulnerability in Br-Automation VC4 Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. | 9.8 |
2023-02-08 | CVE-2022-43762 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Br-Automation Industrial Automation Aprol Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages | 9.8 |
2023-02-08 | CVE-2022-43764 | Out-of-bounds Write vulnerability in Br-Automation Industrial Automation Aprol Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. | 9.8 |
2020-11-27 | CVE-2019-19875 | Command Injection vulnerability in Br-Automation Industrial Automation Aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. | 10.0 |