CVE-2024-0220
22.02.2024, 11:15
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
Vendor | Product | Version |
---|---|---|
br-automation | automation_studio | 𝑥 < 4.6 |
br-automation | technology_guarding | 𝑥 < 1.4.0 |
𝑥
= Vulnerable software versions