Impact
The vulnerability allows improper validation of certificates in B&R Industrial Automation GmbH APROL, identified as CWE‑295. This flaw can lead to failures in secure communication protocols. An attacker could potentially intercept or inject traffic, forging certificates to conduct man‑in‑the‑middle attacks, or to gain unauthorized access, resulting in disclosure of credentials or compromise of data integrity and confidentiality.
Affected Systems
All APROL devices running firmware versions before R 4.4‑01P5 are affected by this certificate validation issue.
Risk and Exploitability
The CVSS score of 9.1 signals a high severity risk, while active exploitation attempts are unlikely presently. The vulnerability is not included in the CISA KEV catalog, meaning no publicly known exploits are documented. Based on the description, it is inferred that the likely attack vector involves network access to the device, particularly targeting management interfaces that perform certificate validation, and the attacker could intercept or inject traffic or bypass authentication.
OpenCVE Enrichment