PT-2020-10043 · B&R · Automation Studio

Published

2020-04-29

·

Updated

2021-09-14

·

CVE-2019-19100

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions B&R Automation Studio versions 4.0.x through 4.8.0
Description A privilege escalation issue in the upgrade service allows authenticated users to delete arbitrary files via an exposed interface.
Recommendations For versions 4.0.x through 4.8.0, update to version 4.8.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19100

Affected Products

Automation Studio