B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Br-automation
Br-automation automation Studio |
|
Weaknesses | CWE-311 CWE-326 |
|
CPEs | cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:* | |
Vendors & Products |
Br-automation
Br-automation automation Studio |
|
Metrics |
ssvc
|
Thu, 19 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-1240 |
MITRE
Status: PUBLISHED
Assigner: ABB
Published: 2024-02-22T10:15:44.750Z
Updated: 2024-09-19T17:24:51.723Z
Reserved: 2024-01-03T15:46:41.224Z
Link: CVE-2024-0220
Vulnrichment
Updated: 2024-08-01T17:41:15.976Z
NVD
Status : Awaiting Analysis
Published: 2024-02-22T11:15:08.840
Modified: 2024-11-21T08:46:05.430
Link: CVE-2024-0220
Redhat
No data.