CVE-2019-19100: Privilege escalation via B&R Automation Studio upgrade service
A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, <. 4.6.3SP, < 4.7.2 and < 4.8.1 allow authenticated users to delete arbitrary files via an exposed interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19100?
CVE-2019-19100 is classified as a privilege escalation vulnerability.
How do I fix CVE-2019-19100?
To fix CVE-2019-19100, upgrade B&R Automation Studio to version 4.3.11SP or later.
What software versions are affected by CVE-2019-19100?
CVE-2019-19100 affects B&R Automation Studio versions 4.0.x to 4.2.x and below versions 4.3.11SP, 4.4.9SP, 4.5.4SP, 4.6.3SP, 4.7.2, and 4.8.1.
Can authenticated users exploit CVE-2019-19100?
Yes, authenticated users can exploit CVE-2019-19100 to delete arbitrary files via an exposed interface.
Is there a workaround for CVE-2019-19100 while waiting for a patch?
The recommended practice is to restrict access to the upgrade service interface as a temporary measure until the software can be updated.