Skip to main content

Vendor/product archive

br-automation / automation_runtime CVEs

Beta · best-effort

8 CVEs tagged to br-automation / automation_runtime2 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-5800

Published Aug 12, 2024

Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6028

Published Feb 5, 2024

A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote atta…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0323

Published Feb 5, 2024

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-3242

Published Jul 26, 2023

Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4286

Published Feb 14, 2023

A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to e…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22275

Published May 13, 2022

Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of s…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11637

Published Oct 15, 2020

A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1