Br-automation

Industrial Automation Aprol

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.7%
  • Veröffentlicht 27.11.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:34

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnera...

  • EPSS 0.42%
  • Veröffentlicht 27.11.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:34

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.

  • EPSS 0.14%
  • Veröffentlicht 27.11.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:34

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against AprolSqlServer, a different vulnerability than CVE...

  • EPSS 0.33%
  • Veröffentlicht 27.11.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:34

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358.

  • EPSS 0.24%
  • Veröffentlicht 27.11.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:33

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface.

  • EPSS 0.65%
  • Veröffentlicht 27.11.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:33

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-16364.