Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0323

Опубликовано: 05 фев. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:br-automation:automation_runtime:*:*:*:*:*:*:*:*
Версия до i4.93 (включая)

EPSS

Процентиль: 31%
0.00119
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1240

Связанные уязвимости

CVSS3: 9.8
github
около 2 лет назад

Use of a Broken or Risky Cryptographic Algorithm vulnerability in B&R Industrial Automation Automation Runtime (SDM modules). The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.   This issue affects Automation Runtime: from 14.0 before 14.93.

EPSS

Процентиль: 31%
0.00119
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1240