CVE-2020-24681: Automation Studio and PVI Multiple incorrect permission assignments for services
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24681?
CVE-2020-24681 has been classified as a medium severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2020-24681?
To fix CVE-2020-24681, update your B&R Automation Studio installation to version 4.7.7 SP or later, 4.8.6 SP or later, or 4.9.4.92 or later.
What versions of Automation Studio are affected by CVE-2020-24681?
CVE-2020-24681 affects Automation Studio versions from 4.6.0 to 4.6.X, below 4.7.7 SP, below 4.8.6 SP, and below 4.9.4.92.
What type of vulnerability is CVE-2020-24681?
CVE-2020-24681 is identified as an Incorrect Permission Assignment for Critical Resource vulnerability.
Can CVE-2020-24681 impact my system if I use a Windows operating system?
CVE-2020-24681 affects B&R Automation Studio and does not impact systems using the Windows operating system alone.