
CVE-2024-8603
https://notcve.org/view.php?id=CVE-2024-8603
15 Jan 2025 — A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices. • https://www.br-automation.com/fileadmin/SA25P001-c478fad6.pdf • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2024-5801 – IP Forwarding enabled in B&R Automation Runtime
https://notcve.org/view.php?id=CVE-2024-5801
10 Aug 2024 — Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering. • https://www.br-automation.com/fileadmin/SA24P011-d8aaf02f.pdf • CWE-653: Improper Isolation or Compartmentalization CWE-1188: Initialization of a Resource with an Insecure Default •

CVE-2024-5800 – Diffie-Hellman groups with insufficient strength used in SSL/TLS stack of B&R Automation Runtime
https://notcve.org/view.php?id=CVE-2024-5800
10 Aug 2024 — Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication. • https://www.br-automation.com/fileadmin/SA24P011-d8aaf02f.pdf • CWE-326: Inadequate Encryption Strength •