CVE-2019-19872: Command Injection
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-16364.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19872?
CVE-2019-19872 is classified as a medium severity vulnerability due to its potential for executing arbitrary commands.
How do I fix CVE-2019-19872?
To fix CVE-2019-19872, update B&R Industrial Automation APROL to version R4.2 V7.08 or later.
What type of attacks are possible with CVE-2019-19872?
CVE-2019-19872 allows attackers to inject and execute arbitrary unintended commands via an unspecified attack scenario.
Which versions of APROL are affected by CVE-2019-19872?
APROL versions prior to R4.2 V7.08 are affected by CVE-2019-19872.
Is CVE-2019-19872 related to any other vulnerabilities?
CVE-2019-19872 is a different vulnerability from CVE-2019-16364, despite both affecting B&R Industrial Automation products.