CVE-2024-0220: B&R products use insufficient communication encryption
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0220?
CVE-2024-0220 has a critical severity rating due to the potential for arbitrary code execution and data exposure.
How do I fix CVE-2024-0220?
To mitigate CVE-2024-0220, upgrade to the latest version of B&R Automation Studio and B&R Technology Guarding that addresses the cryptographic vulnerabilities.
What products are affected by CVE-2024-0220?
CVE-2024-0220 affects B&R Automation Studio Upgrade Service and B&R Technology Guarding.
Can CVE-2024-0220 be exploited remotely?
Yes, CVE-2024-0220 can be exploited remotely by a network-based attacker.
What kind of attacks can CVE-2024-0220 enable?
CVE-2024-0220 allows attackers to execute arbitrary code or sniff sensitive data transmitted between the affected products and servers.