Vulnerabilities > BR Automation > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-0323 Use of a Risky Cryptographic Primitive vulnerability in Br-Automation Automation Runtime
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1.
network
low complexity
br-automation CWE-1240
critical
9.8
2023-04-14 CVE-2023-1617 Improper Authentication vulnerability in Br-Automation VC4
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices.
network
low complexity
br-automation CWE-287
critical
9.8
2023-02-08 CVE-2022-43762 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Br-Automation Industrial Automation Aprol
 Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages
network
low complexity
br-automation CWE-119
critical
9.8
2023-02-08 CVE-2022-43764 Out-of-bounds Write vulnerability in Br-Automation Industrial Automation Aprol
Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow.
network
low complexity
br-automation CWE-787
critical
9.8
2020-11-27 CVE-2019-19875 Command Injection vulnerability in Br-Automation Industrial Automation Aprol
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08.
network
low complexity
br-automation CWE-77
critical
10.0