B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
History

Thu, 19 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Br-automation
Br-automation automation Studio
Weaknesses CWE-311
CWE-326
CPEs cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*
Vendors & Products Br-automation
Br-automation automation Studio
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1240

cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published: 2024-02-22T10:15:44.750Z

Updated: 2024-09-19T17:24:51.723Z

Reserved: 2024-01-03T15:46:41.224Z

Link: CVE-2024-0220

cve-icon Vulnrichment

Updated: 2024-08-01T17:41:15.976Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-22T11:15:08.840

Modified: 2024-11-21T08:46:05.430

Link: CVE-2024-0220

cve-icon Redhat

No data.