CVE-2020-11637

A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
ABBCNA
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
br-automationautomation_runtime
𝑥
≤ 4.10
br-automationautomation_runtime
4.20 ≤
br-automationautomation_runtime
4.40 ≤
br-automationautomation_runtime
4.50 ≤
br-automationautomation_runtime
4.60 ≤
br-automationautomation_runtime
4.70 ≤
br-automationautomation_runtime
4.30 ≤
𝑥
= Vulnerable software versions