Sploit.io - Search

Product: B&R APROL, version: < R 4.2-07

CVE-2022-43761

Severity: CRITICAL

Description: Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. 

CVSS Score: 9.4

Affected Products:

  • B&R Industrial Automation B&R APROL - Versions: < R 4.2-07

References:

CVE-2022-43762

Severity: HIGH

Description:  Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages

CVSS Score: 7.5

Affected Products:

  • B&R Industrial Automation B&R APROL - Versions: < R 4.2-07

References:

CVE-2022-43763

Severity: HIGH

Description: Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.

CVSS Score: 7.5

Affected Products:

  • B&R Industrial Automation B&R APROL - Versions: < R 4.2-07

References:

CVE-2022-43764

Severity: CRITICAL

Description: Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

CVSS Score: 9.8

Affected Products:

  • B&R Industrial Automation B&R APROL - Versions: < R 4.2-07

References:

CVE-2022-43765

Severity: HIGH

Description: B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.

CVSS Score: 7.5

Affected Products:

  • B&R Industrial Automation B&R APROL - Versions: < R 4.2-07

References: