Impact
The vulnerability is an improper certificate validation flaw in B&R Industrial Automation GmbH APROL. It occurs when certificates are not correctly verified during secure communication setups. The result is a failure in the expected integrity or authenticity checks that secure protocols rely on, potentially allowing a connector to accept a certificate that should have been rejected. This flaw is categorized under CWE-295.
Affected Systems
All APROL devices running firmware versions before R 4.4‑01P5 are affected. The issue applies to the APROL product line from B&R Industrial Automation GmbH.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. The EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known exploits are documented. Based on the description, it is inferred that the likely attack vector involves network access to the device’s management interface where certificate validation occurs, and an attacker could attempt to supply a forged or otherwise malformed certificate to gain unauthorized access or disrupt secure communications.
OpenCVE Enrichment