First published: Tue Mar 25 2025(Updated: )
A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
B&R APROL | <4.4-00P5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10206 is categorized as a high severity vulnerability due to the potential for unauthenticated exploitation.
To remediate CVE-2024-10206, update the B&R APROL Web Portal to version 4.4-00P5 or later.
CVE-2024-10206 affects users of B&R APROL Web Portal versions prior to 4.4-00P5.
CVE-2024-10206 enables a Server-Side Request Forgery attack, allowing attackers to access internal resources.
No, CVE-2024-10206 can be exploited by unauthenticated network-based attackers.