Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:HBr Automation Automation Studio
APPBr-Automation4.0 – 4.12 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2019-19108CRITICAL9.4PL ✓same product
Słabe uwierzytelnianie SNMP w B&R Automation Runtime umożliwia modyfikację konfiguracji
CVE-2024-0220HIGH8.3same product
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communicat...
CVE-2020-24681HIGH8.2same product
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation St...
CVE-2020-24682HIGH7.2same product
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial A...
CVE-2021-22282HIGH8.3same product
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automatio...