First published: Tue Sep 29 2020(Updated: )
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
B&R Industrial Automation GmbH SiteManager | ||
B&R Industrial Automation GmbH GateManager | ||
B&R Industrial Automation GmbH GateManager | ||
B&R Industrial Automation SiteManager | <9.2.620236042 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11641 is classified as a medium-severity vulnerability due to its potential for exposing sensitive files.
To mitigate CVE-2020-11641, upgrade B&R SiteManager to version 9.2.620236042 or later.
CVE-2020-11641 affects all versions of B&R SiteManager prior to 9.2.620236042, as well as older versions of GateManager 4260 and 9250, and GateManager 8250.
CVE-2020-11641 is a local file inclusion vulnerability that allows authenticated users access to sensitive files.
CVE-2020-11641 cannot be exploited remotely as it requires authenticated user access to the affected system.