PT-2025-3702 · B&R · B&R Automation Runtime+1
Published
2025-01-15
·
Updated
2025-02-06
·
CVE-2024-8603
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
B&R Automation Runtime versions prior to 6.1
B&R mapp View versions prior to 6.1
Description
A "Use of a Broken or Risky Cryptographic Algorithm" issue in the SSL/TLS component may be exploited by unauthenticated network-based attackers to masquerade as services on impacted devices. This issue is being actively exploited.
Recommendations
For B&R Automation Runtime versions prior to 6.1, update to version 6.1 or later to resolve the issue.
For B&R mapp View versions prior to 6.1, update to version 6.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the SSL/TLS component until a patch is available.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B&R Automation Runtime
B&R Mapp View