PT-2020-10050 · B&R · B&R Automation Runtime
Published
2020-04-20
·
Updated
2020-04-29
·
CVE-2019-19108
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 through 3.10, 4.00 through 4.63, 4.72 and above
Description
An authentication weakness in the SNMP service allows unauthenticated users to modify the configuration of B&R products via SNMP.
Recommendations
For versions 2.96, 3.00, 3.01, 3.06 through 3.10, 4.00 through 4.63, 4.72 and above, consider disabling the SNMP service until a patch is available to prevent unauthenticated modification of the configuration. Restrict access to the SNMP service to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B&R Automation Runtime