Back to Database
Status published
Medium
CVE-2024-10206
Server-Side Request Forgery (unauthenticated) in APROL Web Portal
Vulnerability Description
A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10206
Credits & Attribution
No credits recorded in the NVD database.
More from B&R Industrial Automation GmbH
View All →CVE-2025-3449
Weak Session Token used in Automation Runtime SDM
Low
2.3
CVE-2025-3448
XSS on SDM
Medium
5.1
CVE-2025-11498
CSV Formula Injection Vulnerability
Medium
5.3
CVE-2025-11482
Allocation of Resources Without Limits or Throttling in the OPC-UA Server
High
8.7
CVE-2025-11044
Vulnerability on Automation Runtime my cause DoS Conditions
High
8.9
Affected Vendor
B&R Industrial Automation GmbH
View all reports →Affected Software
APROL
Vulnerable Versions:
4.4-00
Timeline
Official Publish:
March 25th, 2025
Last Modified:
March 25th, 2025
Added to House:
July 22nd, 2026