Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Privilege escalation via B&R Automation Studio upgrade service
Vulnerability Description
A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, <. 4.6.3SP, < 4.7.2 and < 4.8.1 allow authenticated users to delete arbitrary files via an exposed interface.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
Vulnerability Type
权限、特权和访问控制
Vulnerability Title
B&R Automation Studio 安全漏洞
Vulnerability Description
B&R Automation Studio是奥地利贝加莱工业自动化(B&R Automation)公司的一套集成化的软件开发环境。 B&R Automation Studio中的更新服务存在提权漏洞。攻击者可利用该漏洞删除任意文件。以下产品及版本受到影响:Automation Studio 4.0.x版本,4.1.x版本,4.2.x版本,4.3.11SP之前版本,4.4.9SP之前版本,4.5.4SP之前版本,4.6.3SP之前版本,4.7.2之前版本,4.8.1之前版本。
CVSS Information
N/A
Vulnerability Type
N/A