CVE-2024-10206: Server-Side Request Forgery (unauthenticated) in APROL Web Portal
Published Mar 25, 2025
·Updated
A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.
Affected Software
1 affected component
B&R APROL Web Portal<4.4-00P5
Event History
Mar 25, 2025
CVE Published
via MITRE·04:33 AM
Data Sourced
via MITRE·04:33 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10206?
CVE-2024-10206 is categorized as a high severity vulnerability due to the potential for unauthenticated exploitation.
2
How can I fix CVE-2024-10206?
To remediate CVE-2024-10206, update the B&R APROL Web Portal to version 4.4-00P5 or later.
3
Who is affected by CVE-2024-10206?
CVE-2024-10206 affects users of B&R APROL Web Portal versions prior to 4.4-00P5.
4
What type of attack does CVE-2024-10206 enable?
CVE-2024-10206 enables a Server-Side Request Forgery attack, allowing attackers to access internal resources.
5
Is authentication required to exploit CVE-2024-10206?
No, CVE-2024-10206 can be exploited by unauthenticated network-based attackers.