CVE-2020-11646: GateManager Log Information Disclosure Vulnerability
A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log information reserved for other users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11646 vulnerability about?
It is a log information disclosure vulnerability in B&R GateManager versions <9.0.20262 and <9.2.620236042 allowing authenticated users to view logs meant for other users.
How severe is CVE-2020-11646?
The severity of CVE-2020-11646 is rated as 4.3 (medium).
How can I check if my B&R GateManager version is affected?
Check if your B&R GateManager version is less than 9.0.20262 for 4260, less than 9.0.20262 for 9250, and less than 9.2.620236042 for 8250.
Is exploitation of CVE-2020-11646 restricted to authenticated users?
Yes, exploitation of CVE-2020-11646 requires authenticated access to the B&R GateManager.
Are there any official references for CVE-2020-11646?
Yes, official references for CVE-2020-11646 can be found on the US-CERT CISA website and the B&R Automation product documentation.