PT-2025-12730 · B&R · B&R Aprol
Published
2025-03-24
·
Updated
2025-03-25
·
CVE-2024-45482
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
B&R APROL versions prior to 4.4-00P1
Description
The issue is related to an Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server, which may allow an authenticated local attacker from a trusted remote server to execute malicious commands. This could potentially be exploited by a trusted remote attacker to execute commands.
Recommendations
For versions prior to 4.4-00P1, update to version 4.4-00P1 or later to secure against attacks. As a temporary workaround, consider restricting access to the SSH server until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B&R Aprol