CVE-2019-19869: High severity b&r industrial automation aprol vulnerability
Published Nov 27, 2020
·Updated
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface.
Affected Software
1 affected component
Br-automation Industrial Automation Aprol<r4.2
Event History
Nov 27, 2020
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19869?
CVE-2019-19869 has been classified as a high severity vulnerability due to the potential for unauthorized changes to process variables.
2
How do I fix CVE-2019-19869?
To mitigate CVE-2019-19869, update to B&R Industrial Automation APROL version R4.2 V7.08 or later.
3
What is the impact of CVE-2019-19869 on B&R Industrial Automation APROL users?
The impact of CVE-2019-19869 allows attackers to modify unencrypted process variables, leading to potential unauthorized actions.
4
Are there any known exploits for CVE-2019-19869?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2019-19869.
5
Which versions of B&R Industrial Automation APROL are affected by CVE-2019-19869?
All versions of B&R Industrial Automation APROL prior to R4.2 V7.08 are affected by CVE-2019-19869.