First published: Thu Feb 22 2024(Updated: )
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Automation Studio | <4.6 | |
B&R Automation Technology Guarding | <1.4.0 | |
B&R Automation Studio Upgrade Service | ||
B&R Automation Technology Guarding |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0220 has a critical severity rating due to the potential for arbitrary code execution and data exposure.
To mitigate CVE-2024-0220, upgrade to the latest version of B&R Automation Studio and B&R Technology Guarding that addresses the cryptographic vulnerabilities.
CVE-2024-0220 affects B&R Automation Studio Upgrade Service and B&R Technology Guarding.
Yes, CVE-2024-0220 can be exploited remotely by a network-based attacker.
CVE-2024-0220 allows attackers to execute arbitrary code or sniff sensitive data transmitted between the affected products and servers.