CVE-2020-11641: SiteManager Local File Inclusion Vulnerability
Published Oct 15, 2020
·Updated
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.
Affected Software
4 affected components
B&R Industrial Automation GmbH SiteManager all versions prior to v9.2.620236042
B&R Industrial Automation GmbH GateManager 4260 and 9250 all versions prior to v9.0.20262
B&R Industrial Automation GmbH GateManager 8250 all versions prior to v9.2.620236042
Br-automation Sitemanager<9.2.620236042
Event History
Oct 15, 2020
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-11641?
CVE-2020-11641 is classified as a medium-severity vulnerability due to its potential for exposing sensitive files.
2
How do I fix CVE-2020-11641?
To mitigate CVE-2020-11641, upgrade B&R SiteManager to version 9.2.620236042 or later.
3
Who is affected by CVE-2020-11641?
CVE-2020-11641 affects all versions of B&R SiteManager prior to 9.2.620236042, as well as older versions of GateManager 4260 and 9250, and GateManager 8250.
4
What type of vulnerability is CVE-2020-11641?
CVE-2020-11641 is a local file inclusion vulnerability that allows authenticated users access to sensitive files.
5
Can CVE-2020-11641 be exploited remotely?
CVE-2020-11641 cannot be exploited remotely as it requires authenticated user access to the affected system.