Vulnerability Description
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Br-Automation | Automation Studio | < 4.6 |
| Br-Automation | Technology Guarding | < 1.4.0 |
Related Weaknesses (CWE)
References
- https://www.br-automation.com/fileadmin/SA23P019_Automation_Studio_Upgrade_ServiVendor Advisory
- https://www.br-automation.com/fileadmin/SA23P019_Automation_Studio_Upgrade_ServiVendor Advisory
FAQ
What is CVE-2024-0220?
CVE-2024-0220 is a vulnerability with a CVSS score of 8.3 (HIGH). B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the v...
How severe is CVE-2024-0220?
CVE-2024-0220 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0220?
Check the references section above for vendor advisories and patch information. Affected products include: Br-Automation Automation Studio, Br-Automation Technology Guarding.