CVE-2019-19108
20.04.2020, 22:15
An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.Enginsight
| Vendor | Product | Version |
|---|---|---|
| br-automation | automation_runtime | 3.08 ≤ 𝑥 ≤ 3.10 |
| br-automation | automation_runtime | 4.00 ≤ 𝑥 ≤ 4.03 |
| br-automation | automation_runtime | 4.04 ≤ 𝑥 ≤ 4.63 |
| br-automation | automation_runtime | 2.96 |
| br-automation | automation_runtime | 3.00 |
| br-automation | automation_runtime | 3.01 |
| br-automation | automation_runtime | 3.06 |
| br-automation | automation_runtime | 3.07 |
| br-automation | automation_runtime | 4.72 |
| br-automation | automation_studio | 4.0.0 ≤ 𝑥 ≤ 4.6.4 |
| br-automation | automation_studio | 2.7 |
| br-automation | automation_studio | 3.0.71 |
| br-automation | automation_studio | 3.0.80 |
| br-automation | automation_studio | 3.0.81 |
| br-automation | automation_studio | 3.0.90 |
| br-automation | automation_studio | 4.7.2 |
𝑥
= Vulnerable software versions
References