Description
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL.

This issue affects APROL: before R 4.4-01P5.
Published: 2026-07-06
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows improper validation of certificates in B&R Industrial Automation GmbH APROL, identified as CWE‑295. This flaw can lead to failures in secure communication protocols. An attacker could potentially intercept or inject traffic, forging certificates to conduct man‑in‑the‑middle attacks, or to gain unauthorized access, resulting in disclosure of credentials or compromise of data integrity and confidentiality.

Affected Systems

All APROL devices running firmware versions before R 4.4‑01P5 are affected by this certificate validation issue.

Risk and Exploitability

The CVSS score of 9.1 signals a high severity risk, while active exploitation attempts are unlikely presently. The vulnerability is not included in the CISA KEV catalog, meaning no publicly known exploits are documented. Based on the description, it is inferred that the likely attack vector involves network access to the device, particularly targeting management interfaces that perform certificate validation, and the attacker could intercept or inject traffic or bypass authentication.

Generated by OpenCVE AI on July 23, 2026 at 14:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent firmware update that addresses devices.
  • If an update is not yet deployed, restrict the device to a trusted isolated network segment, enforce strict access control, and manually verify any certificates presented to management interfaces.
  • Continuously monitor system logs for authentication failures, unexpected certificate warnings, or anomalous traffic, and investigate any suspicious events promptly.

Generated by OpenCVE AI on July 23, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Br-automation
Br-automation industrial Automation Aprol
Vendors & Products Br-automation
Br-automation industrial Automation Aprol

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
Title Improper Certificate Validation
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Br-automation Industrial Automation Aprol
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2026-07-06T18:49:35.645Z

Reserved: 2026-04-23T08:25:59.674Z

Link: CVE-2026-6900

cve-icon Vulnrichment

Updated: 2026-07-06T18:49:31.688Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T15:00:14Z

Weaknesses
  • CWE-295

    Improper Certificate Validation