CVE-2019-19102: Zip Slip vulnerability in 3rd-Party library in B&R Automation Studio upgrade service
A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories. The vulnerability is also known as zip slip.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19102?
CVE-2019-19102 has a high severity rating due to its potential for unauthenticated access to local directories.
How do I fix CVE-2019-19102?
To fix CVE-2019-19102, upgrade to the latest patched version of B&R Automation Studio specified by the vendor.
Which versions of B&R Automation Studio are affected by CVE-2019-19102?
CVE-2019-19102 affects B&R Automation Studio versions 4.0.x, 4.1.x, and 4.2.x up to their respective patched versions.
Can CVE-2019-19102 be exploited remotely?
CVE-2019-19102 can be exploited by unauthenticated users if they can access the upgrade service.
What type of attack does CVE-2019-19102 allow?
CVE-2019-19102 allows directory traversal attacks, enabling unauthorized file writes to local directories.