Back to Database
Status published
High
CVE-2024-10209
Incorrect Permission Assignment in APROL file system
Vulnerability Description
An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10209
Credits & Attribution
No credits recorded in the NVD database.
More from B&R Industrial Automation GmbH
View All →CVE-2025-3449
Weak Session Token used in Automation Runtime SDM
Low
2.3
CVE-2025-3448
XSS on SDM
Medium
5.1
CVE-2025-11498
CSV Formula Injection Vulnerability
Medium
5.3
CVE-2025-11482
Allocation of Resources Without Limits or Throttling in the OPC-UA Server
High
8.7
CVE-2025-11044
Vulnerability on Automation Runtime my cause DoS Conditions
High
8.9
Affected Vendor
B&R Industrial Automation GmbH
View all reports →Affected Software
APROL
Vulnerable Versions:
4.4
Timeline
Official Publish:
March 25th, 2025
Last Modified:
March 25th, 2025
Added to House:
July 22nd, 2026