B&R products use insufficient communication encryption
Vulnerability Description
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0220
Credits & Attribution
No credits recorded in the NVD database.
More from B&R Industrial Automation
View All →Affected Vendor
B&R Industrial Automation
View all reports →