- EPSS 0.7%
- Veröffentlicht 27.11.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:34
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnera...
CVE-2019-19876
- EPSS 0.42%
- Veröffentlicht 27.11.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:34
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.
CVE-2019-19877
- EPSS 0.14%
- Veröffentlicht 27.11.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:34
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against AprolSqlServer, a different vulnerability than CVE...
CVE-2019-19878
- EPSS 0.33%
- Veröffentlicht 27.11.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:34
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358.
CVE-2019-19869
- EPSS 0.24%
- Veröffentlicht 27.11.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:33
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface.
CVE-2019-19872
- EPSS 0.65%
- Veröffentlicht 27.11.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:33
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-16364.