Vulnerabilities > BR Automation > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-05 | CVE-2024-0323 | Unspecified vulnerability in Br-Automation Automation Runtime The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. | 9.8 |
2023-04-14 | CVE-2023-1617 | Improper Authentication vulnerability in Br-Automation VC4 Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. | 9.8 |
2023-02-08 | CVE-2022-43762 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Br-Automation Industrial Automation Aprol Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages | 9.8 |
2023-02-08 | CVE-2022-43764 | Out-of-bounds Write vulnerability in Br-Automation Industrial Automation Aprol Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. | 9.8 |
2022-08-11 | CVE-2021-22289 | Improper Input Validation vulnerability in Br-Automation Studio Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code. | 9.8 |
2020-11-27 | CVE-2019-19876 | SQL Injection vulnerability in Br-Automation Industrial Automation Aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. | 9.8 |
2020-11-27 | CVE-2019-19875 | Command Injection vulnerability in Br-Automation Industrial Automation Aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. | 9.8 |
2020-11-27 | CVE-2019-19874 | Command Injection vulnerability in Br-Automation Industrial Automation Aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. | 9.8 |
2020-11-27 | CVE-2019-19872 | Command Injection vulnerability in Br-Automation Industrial Automation Aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. | 9.8 |
2020-04-20 | CVE-2019-19108 | Use of Hard-coded Credentials vulnerability in Br-Automation Automation Studio An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP. | 9.4 |