PT-2024-10790 · B&R Industrial Automation · Automation Studio+1

Published

2024-02-02

·

Updated

2024-02-10

·

CVE-2020-24682

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions B&R Industrial Automation Automation Studio versions 4.0 through 4.6, versions 4.7.0 through 4.7.6, versions 4.8.0 through 4.8.5, versions 4.9.0 through 4.9.3 B&R Industrial Automation NET/PVI versions 4.0 through 4.6, versions 4.7.0 through 4.7.6, versions 4.8.0 through 4.8.5, versions 4.9.0 through 4.9.3
Description The issue is related to an Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio and B&R Industrial Automation NET/PVI, allowing target programs to run with elevated privileges.
Recommendations For Automation Studio versions 4.0 through 4.6, update to version 4.7.7 SP or later. For Automation Studio versions 4.7.0 through 4.7.6, update to version 4.7.7 SP or later. For Automation Studio versions 4.8.0 through 4.8.5, update to version 4.8.6 SP or later. For Automation Studio versions 4.9.0 through 4.9.3, update to version 4.9.4 SP or later. For NET/PVI versions 4.0 through 4.6, update to version 4.7.7 or later. For NET/PVI versions 4.7.0 through 4.7.6, update to version 4.7.7 or later. For NET/PVI versions 4.8.0 through 4.8.5, update to version 4.8.6 or later. For NET/PVI versions 4.9.0 through 4.9.3, update to version 4.9.4 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-24682

Affected Products

Automation Studio
Net/Pvi