PT-2020-10050 · B&R · B&R Automation Runtime

Published

2020-04-20

·

Updated

2020-04-29

·

CVE-2019-19108

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 through 3.10, 4.00 through 4.63, 4.72 and above
Description An authentication weakness in the SNMP service allows unauthenticated users to modify the configuration of B&R products via SNMP.
Recommendations For versions 2.96, 3.00, 3.01, 3.06 through 3.10, 4.00 through 4.63, 4.72 and above, consider disabling the SNMP service until a patch is available to prevent unauthenticated modification of the configuration. Restrict access to the SNMP service to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19108

Affected Products

B&R Automation Runtime