VYPR
Unrated severityNVD Advisory· Published Oct 15, 2020· Updated Sep 17, 2024

GateManager Information Disclosure Vulnerability

CVE-2020-11643

Description

An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated attacker can read device information belonging to foreign domains in B&R GateManager before specific patches.

Vulnerability

An information disclosure vulnerability exists in B&R GateManager 4260 and 9250 versions prior to 9.0.20262 and GateManager 8250 versions prior to 9.2.620236042. The flaw allows authenticated users to view information of devices that belong to foreign domains, violating intended domain isolation. The vulnerability is classified as CWE-200 Information Exposure [1].

Exploitation

An attacker must have valid authentication credentials to a GateManager instance. No special network position is required beyond network access to the management interface. The attacker can then exploit the missing proper access controls that should restrict device information visibility to the user's own domain. The reference notes low skill level to exploit [1].

Impact

Successful exploitation allows an authenticated attacker to gather information about devices belonging to a foreign organization. This information could then be abused for further malicious activities, leading to a confidentiality impact with a CVSS v3 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) [1].

Mitigation

B&R has released GateManager 4260 and 9250 version 9.0.20262 and GateManager 8250 version 9.2.620236042 to address this vulnerability. Users should upgrade to these fixed versions or later. The CISA advisory (ICSA-20-273-03) provides the official vendor notification [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • <9.0.20262 for 4260 and 9250; <9.2.620236042 for 8250+ 1 more
    • (no CPE)range: <9.0.20262 for 4260 and 9250; <9.2.620236042 for 8250
    • (no CPE)range: 4260

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.