Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0220

Опубликовано: 22 фев. 2024
Источник: nvd
CVSS3: 8.3
CVSS3: 8.1
EPSS Низкий

Описание

B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*
Версия до 4.6 (исключая)
cpe:2.3:a:br-automation:technology_guarding:*:*:*:*:*:*:*:*
Версия до 1.4.0 (исключая)

EPSS

Процентиль: 43%
0.00205
Низкий

8.3 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.3
github
почти 2 года назад

B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data. Missing Encryption of Sensitive Data, Cleartext Transmission of Sensitive Information, Improper Control of Generation of Code ('Code Injection'), Inadequate Encryption Strength vulnerability in B&R Industrial Automation B&R Automation Studio (Upgrade Service modules), B&R Industrial Automation Technology Guarding.This issue affects B&R Automation Studio: <4.6; Technology Guarding: <1.4.0.

EPSS

Процентиль: 43%
0.00205
Низкий

8.3 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-94