Description
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16019 | B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data. |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 06 May 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Br-automation technology Guarding
|
|
| CPEs | cpe:2.3:a:br-automation:technology_guarding:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Br-automation technology Guarding
|
Thu, 19 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Br-automation
Br-automation automation Studio |
|
| Weaknesses | CWE-311 CWE-326 |
|
| CPEs | cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Br-automation
Br-automation automation Studio |
|
| Metrics |
ssvc
|
Thu, 19 Sep 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1240 |
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-09-19T17:24:51.723Z
Reserved: 2024-01-03T15:46:41.224Z
Link: CVE-2024-0220
Updated: 2024-08-01T17:41:15.976Z
Status : Analyzed
Published: 2024-02-22T11:15:08.840
Modified: 2025-05-06T17:28:17.343
Link: CVE-2024-0220
No data.
OpenCVE Enrichment
No data.
EUVD