VYPR

Vendor CVEs

B&R Industrial Automation

All CVEs

67 total · sorted by risk
  • CVE-2025-3450CriOct 7, 2025
    risk 0.65cvss 10.0epss 0.00

    An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.

  • CVE-2024-0323CriFeb 5, 2024
    risk 0.64cvss 9.8epss 0.00

    The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.

  • CVE-2023-1617CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this…

  • CVE-2022-43764CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

  • CVE-2019-19876CriNov 27, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.

  • CVE-2019-19875CriNov 27, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnerability than CVE-2019-16364.

  • CVE-2019-19874CriNov 27, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.

  • CVE-2019-19872CriNov 27, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-16364.

  • CVE-2022-43761CriFeb 8, 2023
    risk 0.61cvss 9.4epss 0.01

    Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. 

  • CVE-2019-19108CriApr 20, 2020
    risk 0.61cvss 9.4epss 0.02

    An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.

  • CVE-2024-45480CriMar 25, 2025
    risk 0.60cvss epss 0.00

    An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system.

  • CVE-2024-8313HigMar 25, 2025
    risk 0.57cvss epss 0.00

    An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration…

  • CVE-2023-3242HigJul 26, 2023
    risk 0.56cvss 8.6epss 0.01

    Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.

  • CVE-2021-22275HigMay 13, 2022
    risk 0.56cvss 8.6epss 0.01

    Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.

  • CVE-2024-10210HigMar 25, 2025
    risk 0.55cvss epss 0.00

    An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker to access data from the file system.

  • CVE-2024-45482HigMar 25, 2025
    risk 0.55cvss epss 0.00

    An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an authenticated local attacker from a trusted remote server to execute malicious commands.

  • CVE-2024-45481HigMar 25, 2025
    risk 0.55cvss epss 0.00

    An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may allow an authenticated local attacker to authenticate as another legitimate user.

  • CVE-2024-10209HigMar 25, 2025
    risk 0.55cvss epss 0.00

    An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user.

  • CVE-2024-10490HigDec 2, 2024
    risk 0.55cvss epss 0.00

    An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be…

  • CVE-2024-0220HigFeb 22, 2024
    risk 0.54cvss 8.3epss 0.00

    B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.

  • CVE-2021-22282HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.

  • CVE-2021-22289HigAug 11, 2022
    risk 0.54cvss 8.3epss 0.01

    Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.

  • CVE-2020-24681HigFeb 2, 2024
    risk 0.53cvss 8.2epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0…

  • CVE-2024-5623HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.

  • CVE-2024-5622HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.

  • CVE-2020-11642HigOct 15, 2020
    risk 0.50cvss 7.7epss 0.01

    The local file inclusion vulnerability present in B&R SiteManager versions <9.2.620236042 allows authenticated users to impact availability of SiteManager instances.

  • CVE-2020-11641HigOct 15, 2020
    risk 0.50cvss 7.7epss 0.01

    A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.

  • CVE-2024-8603HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.00

    A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted…

  • CVE-2024-5800HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.00

    Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.

  • CVE-2022-43765HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.01

    B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.

  • CVE-2022-43763HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.

  • CVE-2022-43762HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.01

     Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages

  • CVE-2019-19878HigNov 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358.

  • CVE-2019-19873HigNov 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability than CVE-2019-16356 and CVE-2019-9983.

  • CVE-2019-19869HigNov 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface.

  • CVE-2019-19100HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.00

    A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, <. 4.6.3SP, < 4.7.2 and < 4.8.1 allow authenticated users to delete arbitrary files via an exposed interface.

  • CVE-2025-11043HigJan 19, 2026
    risk 0.48cvss 7.4epss 0.00

    An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges.

  • CVE-2024-45484HigMar 25, 2025
    risk 0.47cvss epss 0.00

    An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL <4.4-00P5 may allow an unauthenticated adjacent attacker to per-form Denial-of-Service (DoS) attacks against the product.

  • CVE-2021-22280HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.

  • CVE-2024-2637HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.00

    An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial…

  • CVE-2020-24682HigFeb 2, 2024
    risk 0.47cvss 7.2epss 0.00

    Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0…

  • CVE-2024-45483HigMar 25, 2025
    risk 0.46cvss epss 0.00

    A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical attacker to alter the boot configuration of the operating system.

  • CVE-2024-10206MedMar 25, 2025
    risk 0.45cvss epss 0.00

    A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.

  • CVE-2025-11044MedJan 19, 2026
    risk 0.44cvss 6.8epss 0.00

    An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent…

  • CVE-2024-8315MedMar 25, 2025
    risk 0.44cvss epss 0.00

    An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential information.

  • CVE-2020-11645MedOct 15, 2020
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to limit availability of GateManager instances.

  • CVE-2020-11644MedOct 15, 2020
    risk 0.42cvss 6.5epss 0.01

    The information disclosure vulnerability present in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to generate fake audit log messages.

  • CVE-2020-11643MedOct 15, 2020
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.

  • CVE-2019-19101MedApr 29, 2020
    risk 0.42cvss 6.5epss 0.01

    A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade…

  • CVE-2021-22281MedFeb 2, 2024
    risk 0.41cvss 6.3epss 0.00

    : Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

Page 1 of 2