CVE-2019-19101: Incomplete communication encryption and validation in B&R Automation Studio upgrade service
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19101?
CVE-2019-19101 is a vulnerability in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4, and < 4.7.2 that enables unauthenticated users to perform MITM attacks via the B&R upgrade server.
What is the severity of CVE-2019-19101?
The severity of CVE-2019-19101 is medium with a CVSS score of 5.9.
How can unauthenticated users exploit CVE-2019-19101?
Unauthenticated users can exploit CVE-2019-19101 by performing MITM attacks via the B&R upgrade server.
Which software versions are affected by CVE-2019-19101?
CVE-2019-19101 affects B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4, and < 4.7.2.
How can CVE-2019-19101 be mitigated?
To mitigate CVE-2019-19101, it is recommended to update B&R Automation Studio to a version higher than the vulnerable ones.