First published: Fri Feb 02 2024(Updated: )
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Automation Studio | >=4.0<=4.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22282 is classified as a high severity vulnerability due to its potential for local code execution.
To remediate CVE-2021-22282, users should upgrade their B&R Automation Studio to a version beyond 4.12.
CVE-2021-22282 affects B&R Automation Studio versions ranging from 4.0 to 4.12.
CVE-2021-22282 is an improper control of generation of code vulnerability leading to code injection.
CVE-2021-22282 requires local access to exploit, hence it cannot be exploited remotely.