CVE-2024-10210: Path traversal in APROL Web Portal
Published Mar 25, 2025
·Updated
An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker to access data from the file system.
Affected Software
1 affected component
B&R APROL<4.4-005P
Event History
Mar 25, 2025
CVE Published
via MITRE·05:32 AM
Data Sourced
via MITRE·05:32 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10210?
CVE-2024-10210 is classified as a medium severity vulnerability due to its potential to allow unauthorized data access.
2
How do I fix CVE-2024-10210?
To fix CVE-2024-10210, upgrade to B&R APROL version 4.4-005P or later, which mitigates the vulnerability.
3
What systems are affected by CVE-2024-10210?
CVE-2024-10210 affects B&R APROL versions prior to 4.4-005P.
4
What type of access does CVE-2024-10210 allow?
CVE-2024-10210 allows authenticated network-based attackers to access files on the system.
5
Is user authentication required to exploit CVE-2024-10210?
Yes, CVE-2024-10210 requires authentication to exploit the vulnerability.