First published: Wed Feb 08 2023(Updated: )
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
B&R Industrial Automation Aprol | <r4.2-07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43761 is classified as a high severity vulnerability due to the potential for unauthorized access to system configurations.
To fix CVE-2022-43761, update the B&R APROL database to version R 4.2-07 or later which includes necessary authentication improvements.
The consequences of CVE-2022-43761 include unauthorized reading and modification of system configurations due to missing authentication.
CVE-2022-43761 affects all versions of B&R APROL prior to R 4.2-07.
As of the latest information, there have been reports indicating potential active exploitation of CVE-2022-43761 in the wild.