br-automation CVE Vulnerabilities & Metrics

Focus on br-automation vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About br-automation Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with br-automation. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total br-automation CVEs: 27
Earliest CVE date: 20 Apr 2020, 22:15 UTC
Latest CVE date: 29 Aug 2024, 11:15 UTC

Latest CVE reference: CVE-2024-5624

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -62.5%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -62.5%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical br-automation CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.82

Max CVSS: 7.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 18
4.0-6.9 7
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS br-automation CVEs

These are the five CVEs with the highest CVSS scores for br-automation, sorted by severity first and recency.

All CVEs for br-automation

CVE-2024-5624 br-automation vulnerability CVSS: 0 29 Aug 2024, 11:15 UTC

Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session

CVE-2024-5623 br-automation vulnerability CVSS: 0 29 Aug 2024, 11:15 UTC

An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.

CVE-2024-5622 br-automation vulnerability CVSS: 0 29 Aug 2024, 11:15 UTC

An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.

CVE-2023-6028 br-automation vulnerability CVSS: 0 05 Feb 2024, 18:15 UTC

A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.

CVE-2024-0323 br-automation vulnerability CVSS: 0 05 Feb 2024, 16:15 UTC

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.

CVE-2021-22281 br-automation vulnerability CVSS: 0 02 Feb 2024, 08:15 UTC

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

CVE-2020-24682 br-automation vulnerability CVSS: 0 02 Feb 2024, 08:15 UTC

Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP; NET/PVI: from 4.0 through 4.6, from 4.7.0 before 4.7.7, from 4.8.0 before 4.8.6, from 4.9.0 before 4.9.4.

CVE-2021-22282 br-automation vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.

CVE-2020-24681 br-automation vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP.

CVE-2023-3242 br-automation vulnerability CVSS: 0 26 Jul 2023, 18:15 UTC

Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.

CVE-2023-1617 br-automation vulnerability CVSS: 0 14 Apr 2023, 12:15 UTC

Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this vulnerability depends on the functionality provided in the visualization. This issue affects B&R VC4: from 3.* through 3.96.7, from 4.0* through 4.06.7, from 4.1* through 4.16.3, from 4.2* through 4.26.8, from 4.3* through 4.34.6, from 4.4* through 4.45.1, from 4.5* through 4.45.3, from 4.7* through 4.72.9.

CVE-2022-4286 br-automation vulnerability CVSS: 0 14 Feb 2023, 15:15 UTC

A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.

CVE-2022-43765 br-automation vulnerability CVSS: 0 08 Feb 2023, 11:15 UTC

B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.

CVE-2022-43764 br-automation vulnerability CVSS: 0 08 Feb 2023, 11:15 UTC

Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

CVE-2022-43763 br-automation vulnerability CVSS: 0 08 Feb 2023, 11:15 UTC

Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.

CVE-2022-43762 br-automation vulnerability CVSS: 0 08 Feb 2023, 11:15 UTC

 Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages

CVE-2022-43761 br-automation vulnerability CVSS: 0 08 Feb 2023, 10:15 UTC

Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. 

CVE-2021-22275 br-automation vulnerability CVSS: 7.8 13 May 2022, 15:15 UTC

Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.

CVE-2020-11637 br-automation vulnerability CVSS: 5.0 15 Oct 2020, 16:15 UTC

A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.

CVE-2020-11646 br-automation vulnerability CVSS: 4.0 15 Oct 2020, 15:15 UTC

A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log information reserved for other users.

CVE-2020-11645 br-automation vulnerability CVSS: 4.0 15 Oct 2020, 15:15 UTC

A denial of service vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to limit availability of GateManager instances.

CVE-2020-11644 br-automation vulnerability CVSS: 4.0 15 Oct 2020, 15:15 UTC

The information disclosure vulnerability present in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to generate fake audit log messages.

CVE-2020-11643 br-automation vulnerability CVSS: 4.0 15 Oct 2020, 15:15 UTC

An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.

CVE-2019-19102 br-automation vulnerability CVSS: 5.0 29 Apr 2020, 03:15 UTC

A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories. The vulnerability is also known as zip slip.

CVE-2019-19101 br-automation vulnerability CVSS: 4.3 29 Apr 2020, 03:15 UTC

A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade server.

CVE-2019-19100 br-automation vulnerability CVSS: 3.6 29 Apr 2020, 03:15 UTC

A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, <. 4.6.3SP, < 4.7.2 and < 4.8.1 allow authenticated users to delete arbitrary files via an exposed interface.

CVE-2019-19108 br-automation vulnerability CVSS: 7.5 20 Apr 2020, 22:15 UTC

An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.