PT-2025-12730 · B&R · B&R Aprol

Published

2025-03-24

·

Updated

2025-03-25

·

CVE-2024-45482

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions B&R APROL versions prior to 4.4-00P1
Description The issue is related to an Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server, which may allow an authenticated local attacker from a trusted remote server to execute malicious commands. This could potentially be exploited by a trusted remote attacker to execute commands.
Recommendations For versions prior to 4.4-00P1, update to version 4.4-00P1 or later to secure against attacks. As a temporary workaround, consider restricting access to the SSH server until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05896
CVE-2024-45482

Affected Products

B&R Aprol