CVE-2021-22282: RCE in B&R Automation Studio with crafted project files
Published Feb 2, 2024
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.
Affected Software
1 affected component
Br-automation Automation Studio>=4.0<=4.12
Event History
Feb 2, 2024
CVE Published
via MITRE·06:38 AM
Data Sourced
via MITRE·06:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22282?
CVE-2021-22282 is classified as a high severity vulnerability due to its potential for local code execution.
2
How do I fix CVE-2021-22282?
To remediate CVE-2021-22282, users should upgrade their B&R Automation Studio to a version beyond 4.12.
3
What systems are affected by CVE-2021-22282?
CVE-2021-22282 affects B&R Automation Studio versions ranging from 4.0 to 4.12.
4
What type of vulnerability is CVE-2021-22282?
CVE-2021-22282 is an improper control of generation of code vulnerability leading to code injection.
5
Can CVE-2021-22282 be exploited remotely?
CVE-2021-22282 requires local access to exploit, hence it cannot be exploited remotely.