Back to Database
Status published
Critical
CVE-2019-19108
B&R Automation Runtime SNMP Authentication and Authorization Weakness
Vulnerability Description
An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19108
Credits & Attribution
No credits recorded in the NVD database.
References
More from B&R
View All →CVE-2020-11646
GateManager Log Information Disclosure Vulnerability
Medium
4.3
CVE-2020-11645
GateManager Denial of Service Vulnerability
Medium
6.5
CVE-2020-11644
GateManager Audit Message Spoofing Vulnerability
Medium
6.5
CVE-2020-11643
GateManager Information Disclosure Vulnerability
Medium
6.5
CVE-2020-11642
SiteManager Denial of Service via Local File Inclusion Vulnerability
High
7.7
Affected Vendor
Affected Software
Automation Runtime
Vulnerable Versions:
2 <= 2.96, 3 <= 3.10, 4 <= 4.72
Timeline
Official Publish:
April 20th, 2020
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H