CVE-2022-43761: Lack of authentication when managing APROL database
Published Feb 8, 2023
·Updated
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07
allows reading and changing the system configuration.
Affected Software
1 affected component
Br-automation Industrial Automation Aprol<r4.2-07
Event History
Feb 8, 2023
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-43761?
CVE-2022-43761 is classified as a high severity vulnerability due to the potential for unauthorized access to system configurations.
2
How do I fix CVE-2022-43761?
To fix CVE-2022-43761, update the B&R APROL database to version R 4.2-07 or later which includes necessary authentication improvements.
3
What are the consequences of CVE-2022-43761?
The consequences of CVE-2022-43761 include unauthorized reading and modification of system configurations due to missing authentication.
4
Which versions are affected by CVE-2022-43761?
CVE-2022-43761 affects all versions of B&R APROL prior to R 4.2-07.
5
Is CVE-2022-43761 being actively exploited?
As of the latest information, there have been reports indicating potential active exploitation of CVE-2022-43761 in the wild.