CVE-2019-19108: B&R Automation Runtime SNMP Authentication and Authorization Weakness
An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19108?
CVE-2019-19108 is an authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above that allows unauthenticated users to modify the configuration of B&R products via SNMP.
How severe is CVE-2019-19108?
CVE-2019-19108 has a severity score of 9.4 out of 10, indicating a critical vulnerability.
Which software versions are affected by CVE-2019-19108?
B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above are affected by CVE-2019-19108.
How can an unauthenticated user exploit CVE-2019-19108?
An unauthenticated user can exploit CVE-2019-19108 by using the SNMP service to modify the configuration of B&R products.
Are there any references for CVE-2019-19108?
Yes, you can find more information about CVE-2019-19108 at the following references: [1] [2]