Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v2m-666w-ffm3

Опубликовано: 05 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Use of a Broken or Risky Cryptographic Algorithm vulnerability in B&R Industrial Automation Automation Runtime (SDM modules).

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.  

This issue affects Automation Runtime: from 14.0 before 14.93.

Use of a Broken or Risky Cryptographic Algorithm vulnerability in B&R Industrial Automation Automation Runtime (SDM modules).

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.  

This issue affects Automation Runtime: from 14.0 before 14.93.

EPSS

Процентиль: 31%
0.00119
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1240
CWE-327

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.

EPSS

Процентиль: 31%
0.00119
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1240
CWE-327