GateManager Denial of Service Vulnerability
Description
A denial of service vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to limit availability of GateManager instances.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An authenticated user can repeatedly restart B&R GateManager devices, causing a denial-of-service condition and limiting availability.
Vulnerability
A denial-of-service (DoS) vulnerability exists in B&R GateManager 4260 and 9250 versions prior to 9.0.20262 and GateManager 8250 versions prior to 9.2.620236042. The issue stems from uncontrolled resource consumption (CWE-400) where an authenticated user can repeatedly trigger a restart of GateManager instances, exhausting system resources and preventing normal operation [1].
Exploitation
An attacker must have valid authentication credentials for the GateManager instance. No special privileges beyond standard user authentication are required. The attacker can exploit the vulnerability remotely over the network by sending a sequence of malicious requests that force the device to restart repeatedly [1].
Impact
Successful exploitation leads to a denial-of-service condition, making the GateManager instance unavailable to legitimate users. The availability impact is high, but confidentiality and integrity are not affected. The CVSS v3 base score is 7.7 with vector string (AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H) [1].
Mitigation
B&R has released fixed versions: GateManager 4260 and 9250 should be updated to version 9.0.20262 or later, and GateManager 8250 should be updated to version 9.2.620236042 or later. These updates address the uncontrolled resource consumption vulnerability [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<9.0.20262 for GateManager 4260 and 9250; <9.2.620236042 for GateManager 8250+ 1 more
- (no CPE)range: <9.0.20262 for GateManager 4260 and 9250; <9.2.620236042 for GateManager 8250
- (no CPE)range: 4260
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- us-cert.cisa.gov/ics/advisories/icsa-20-273-03mitrex_refsource_MISC
- www.br-automation.com/downloads_br_productcatalogue/assets/1600003183751-de-original-1.0.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.