Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

B&R Industrial Automation GmbH — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting B&R Industrial Automation GmbH. AI-powered Chinese analysis, POCs, and references for each vulnerability.

B&R Industrial Automation GmbH specializes in industrial automation solutions, including PLCs, HMIs, and motion control systems for manufacturing and process industries. Historically, their products have faced vulnerabilities such as remote code execution, cross-site scripting, and privilege escalation, often stemming from inadequate input validation and default credentials. While no major public incidents have been widely documented, the 16 CVEs on record highlight persistent security challenges in their web interfaces and communication protocols. Their systems' critical infrastructure role makes them attractive targets, necessitating robust patch management and network segmentation to mitigate exploitation risks in industrial environments.

CVE ID Title CVSS Severity Published
CVE-2026-79679 Use of Weak Credentials — mapp Services CWE-1391 8.7 High 2026-09-03
CVE-2026-6901 Untrusted Search Path — APROL CWE-426 7.7 High 2026-07-06
CVE-2026-6900 Improper Certificate Validation — APROL CWE-295 7.4 High 2026-07-06
CVE-2025-11482 Allocation of Resources Without Limits or Throttling in the OPC-UA Server — PPT30 Operating System CWE-770 7.5 High 2026-05-26
CVE-2026-0936 Insertion of Sensitive Information into Logfile — Process Visualization Interface (PVI) CWE-532 5.0 Medium 2026-01-29
CVE-2025-11044 Vulnerability on Automation Runtime my cause DoS Conditions — Automation Runtime CWE-770 6.8 Medium 2026-01-19
CVE-2025-11043 Improper Server Certificate Validation in Automation Studio — B&R Automation Studio CWE-295 7.4 High 2026-01-19
CVE-2025-11498 CSV Formula Injection Vulnerability — Automation Runtime CWE-1236 6.1 Medium 2025-10-14
CVE-2025-3449 Weak Session Token used in Automation Runtime SDM — Automation Runtime CWE-340 4.2 Medium 2025-10-07
CVE-2025-3448 XSS on SDM — Automation Runtime CWE-79 6.1 Medium 2025-10-07
CVE-2024-10210 Path traversal in APROL Web Portal — APROL CWE-73 6.5AI Medium AI 2025-03-25
CVE-2024-45484 Enabled ICMP redirection in B&R APROL — APROL CWE-770 6.5AI Medium AI 2025-03-25
CVE-2024-45483 Missing GRUB password in B&R APROL — APROL CWE-306 6.1AI Medium AI 2025-03-25
CVE-2024-10209 Incorrect Permission Assignment in APROL file system — APROL CWE-732 7.1AI High AI 2025-03-25
CVE-2024-10208 Cross Site Scripting vulnerability in APROL Web Portal — APROL CWE-79 5.4AI Medium AI 2025-03-25
CVE-2024-10207 Server-Side Request Forgery (authenticated) in APROL Web Portal — APROL CWE-918 7.1AI High AI 2025-03-25
CVE-2024-10206 Server-Side Request Forgery (unauthenticated) in APROL Web Portal — APROL CWE-918 8.2AI High AI 2025-03-25
CVE-2024-8314 Improper session handling in B&R APROL — APROL CWE-303 8.8AI High AI 2025-03-25
CVE-2024-8313 Default or Guessable SNMP community names in B&R APROL — APROL CWE-497 8.8AI High AI 2025-03-25
CVE-2024-10490 Authentication bypass flaw in several mapp components — B&R mapp Cockpit CWE-288 9.8 - 2024-12-02

This page lists every published CVE security advisory associated with B&R Industrial Automation GmbH. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.