
CVE-2024-5801 – IP Forwarding enabled in B&R Automation Runtime
https://notcve.org/view.php?id=CVE-2024-5801
10 Aug 2024 — Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering. • https://www.br-automation.com/fileadmin/SA24P011-d8aaf02f.pdf • CWE-653: Improper Isolation or Compartmentalization CWE-1188: Initialization of a Resource with an Insecure Default •

CVE-2024-5800 – Diffie-Hellman groups with insufficient strength used in SSL/TLS stack of B&R Automation Runtime
https://notcve.org/view.php?id=CVE-2024-5800
10 Aug 2024 — Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication. • https://www.br-automation.com/fileadmin/SA24P011-d8aaf02f.pdf • CWE-326: Inadequate Encryption Strength •

CVE-2023-6028 – SDM Web interface vulnerable to XSS
https://notcve.org/view.php?id=CVE-2023-6028
05 Feb 2024 — A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session. Existe una vulnerabilidad de cross-site scripting (XSS) reflejada en la versión SVG de System Diagnostics Manager de B&R Automation Runtime versiones <= G4.93 que permite a un atacante remoto ejecutar código JavaScript arbitrario... • https://www.br-automation.com/fileadmin/SA23P018_SDM_Web_interface_vulnerable_to_XSS-1d75bee8.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-0323 – FTP uses unsecure encryption mechanisms
https://notcve.org/view.php?id=CVE-2024-0323
05 Feb 2024 — The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients. Uso de una vulnerabilidad de algoritmo criptográfico defectuoso o riesgoso en B&R Industrial Automation Automation Runtime (módulos SDM). El servidor FTP utilizado en B&R Automation Runtime admite mecanismos de cifrado no segu... • https://www.br-automation.com/fileadmin/SA23P004_FTP_uses_unsecure_encryption_mechanisms-f57c147c.pdf • CWE-327: Use of a Broken or Risky Cryptographic Algorithm CWE-1240: Use of a Cryptographic Primitive with a Risky Implementation •

CVE-2023-3242
https://notcve.org/view.php?id=CVE-2023-3242
26 Jul 2023 — Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions. • https://www.br-automation.com/downloads_br_productcatalogue/assets/1689787619746-en-original-1.0.pdf • CWE-665: Improper Initialization CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2022-4286 – Reflected Cross-Site Scripting Vulnerabilities in Automation Runtime
https://notcve.org/view.php?id=CVE-2022-4286
14 Feb 2023 — A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session. B&R Systems Diagnostics Manager versions above or equal to 3.00 and below or equal to C4.93 suffer from a cross site scripting vulnerability. • https://packetstorm.news/files/id/171013 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-22275 – Denial of service vulnerability on Automation Runtime webserver
https://notcve.org/view.php?id=CVE-2021-22275
13 May 2022 — Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service. Una vulnerabilidad de desbordamiento del búfer en el servidor web de B&R Automation Runtime permite a un atacante no autenticado basado en la red detener el programa cíclico en el dispositivo y causar una denegación de servicio • https://www.br-automation.com/downloads_br_productcatalogue/assets/1625405588264-en-original-1.0.pdf • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-11637 – Automation Runtime TFTP Service DoS Vulnerability
https://notcve.org/view.php?id=CVE-2020-11637
15 Oct 2020 — A memory leak in the TFTP service in B&R Automation Runtime versions

CVE-2019-19108 – B&R Automation Runtime SNMP Authentication and Authorization Weakness
https://notcve.org/view.php?id=CVE-2019-19108
20 Apr 2020 — An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP. Una debilidad de autenticación en el servicio SNMP en B&R Automation Runtime versiones 2.96, 3.00, 3.01, versiones 3.06 hasta 3.10, versiones 4.00 hasta 4.63, 4.72 y superiores, permite a usuarios no autenticados modificar la configuración de los productos B&R por medio de SNMP... • https://www.br-automation.com/en/downloads/012020-automation-runtime-snmp-authentication-weakness • CWE-798: Use of Hard-coded Credentials •