First published: Fri Nov 27 2020(Updated: )
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnerability than CVE-2019-16364.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
B&R Industrial Automation Aprol | <r4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19875 is considered to have a high severity due to the potential for arbitrary command execution with root privileges.
To fix CVE-2019-19875, update your B&R Industrial Automation APROL software to version R4.2 V7.08 or higher.
CVE-2019-19875 is an arbitrary command injection vulnerability that affects the AprolCluster script.
Users of B&R Industrial Automation APROL versions before R4.2 V7.08 are affected by CVE-2019-19875.
CVE-2019-19875 allows an attacker to inject and execute arbitrary commands via Python scripts running with elevated privileges.