Critical severity9.4NVD Advisory· Published Apr 20, 2020· Updated Jun 17, 2026
CVE-2019-19108
CVE-2019-19108
Description
An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:br-automation:automation_runtime:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:br-automation:automation_runtime:*:*:*:*:*:*:*:*range: >=3.08,<=3.10
- cpe:2.3:a:br-automation:automation_runtime:2.96:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_runtime:3.00:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_runtime:3.01:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_runtime:3.06:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_runtime:3.07:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_runtime:4.72:*:*:*:*:*:*:*
- (no CPE)range: 2.96, 3.00, 3.01, 3.06-3.10, 4.00-4.63, 4.72+
- (no CPE)range: 2 <= 2.96
cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*range: >=4.0.0,<=4.6.4
- cpe:2.3:a:br-automation:automation_studio:2.7:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_studio:3.0.71:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_studio:3.0.80:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_studio:3.0.81:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_studio:3.0.90:*:*:*:*:*:*:*
- cpe:2.3:a:br-automation:automation_studio:4.7.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.br-automation.com/en/downloads/012020-automation-runtime-snmp-authentication-weakness/nvdVendor Advisory
- www.us-cert.gov/ics/advisories/icsa-20-051-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.