Vulnerabilities in B&R Industrial Automation GmbH
19 resultsVexday analysis
B&R Industrial Automation acumula 19 CVEs com 2 classificadas como críticas, mas nenhuma sob ataque ativo registrado até o momento. A fraqueza dominante (CWE-770 - alocação excessiva de recursos) sugere problemas de robustez em tratamento de recursos, com 3 vulnerabilidades publicadas nos últimos 90 dias indicando exposição contínua a riscos novos.
CVE-2024-10490HIGHAuthentication bypass flaw in several mapp componentsEPSS 0.5%CVE-2024-10210HIGHPath traversal in APROL Web PortalEPSS 0.4%CVE-2024-10208MEDIUMCross Site Scripting vulnerability in APROL Web PortalEPSS 0.4%CVE-2024-10206MEDIUMServer-Side Request Forgery (unauthenticated) in APROL Web PortalEPSS 0.4%CVE-2024-8314MEDIUMImproper session handling in B&R APROLEPSS 0.3%CVE-2024-10207MEDIUMServer-Side Request Forgery (authenticated) in APROL Web PortalEPSS 0.3%CVE-2025-11482HIGHAllocation of Resources Without Limits or Throttling in the OPC-UA ServerEPSS 0.3%CVE-2025-11044HIGHVulnerability on Automation Runtime my cause DoS ConditionsEPSS 0.3%CVE-2025-11498MEDIUMCSV Formula Injection VulnerabilityEPSS 0.3%CVE-2025-3448MEDIUMXSS on SDMEPSS 0.3%CVE-2024-45483HIGHMissing GRUB password in B&R APROLEPSS 0.2%CVE-2024-8313HIGHDefault or Guessable SNMP community names in B&R APROLEPSS 0.2%CVE-2025-11043CRITICALImproper Server Certificate Validation in Automation StudioEPSS 0.2%CVE-2024-45484HIGHEnabled ICMP redirection in B&R APROLEPSS 0.2%CVE-2025-3449LOWWeak Session Token used in Automation Runtime SDMEPSS 0.2%CVE-2026-6900CRITICALImproper Certificate ValidationEPSS 0.1%CVE-2024-10209HIGHIncorrect Permission Assignment in APROL file systemEPSS 0.1%CVE-2026-6901HIGHUntrusted Search PathEPSS 0.1%CVE-2026-0936MEDIUMInsertion of Sensitive Information into LogfileEPSS 0.1%