First published: Tue Mar 25 2025(Updated: )
An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
B&R APROL Web Portal | <4.4-01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10209 has a severity rating that indicates it poses a significant risk due to incorrect permission assignments in the file system.
To fix CVE-2024-10209, update B&R APROL to version 4.4-01 or later to address the incorrect permission assignments.
CVE-2024-10209 affects users of B&R APROL versions prior to 4.4-01, especially those with authenticated local access.
An authenticated local attacker can read and alter the configuration of other engineering or runtime users due to the incorrect permission assignment.
Until a fix is applied, restricting access to the filesystem and monitoring user permissions can help mitigate risks associated with CVE-2024-10209.