CVE-2021-22280: DLL Hijacking Vulnerability in Automation Studio
Published May 14, 2024
·Updated
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.
Affected Software
2 affected components
B&R Automation Automation Studio>=4.0, <4.12
Br-automation Automation Studio>=4.0<4.12
Event History
May 14, 2024
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-22280?
CVE-2021-22280 is rated as a medium severity vulnerability.
2
How do I fix CVE-2021-22280?
To fix CVE-2021-22280, upgrade B&R Automation Studio to a version 4.12 or higher.
3
Who is affected by CVE-2021-22280?
CVE-2021-22280 affects users of B&R Automation Studio versions from 4.0 to below 4.12.
4
What type of attack does CVE-2021-22280 facilitate?
CVE-2021-22280 allows an authenticated local attacker to execute arbitrary code in the context of the affected application.
5
What are the potential consequences of CVE-2021-22280?
The potential consequences of CVE-2021-22280 include unauthorized code execution, which can compromise system integrity and security.