Skip to main content

Vendor/product archive

br-automation / automation_studio CVEs

Beta · best-effort

10 CVEs tagged to br-automation / automation_studio1 Critical, 6 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2021-22280

Published May 14, 2024

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22281

Published Feb 2, 2024

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22282

Published Feb 2, 2024

Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19102

Published Apr 29, 2020

A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to cer…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19101

Published Apr 29, 2020

A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19100

Published Apr 29, 2020

A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, <. 4.6.3SP, < 4.7.2 and < 4.8.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1