CVE-2024-10490: Authentication bypass flaw in several mapp components
An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions. B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10490?
The severity of CVE-2024-10490 is classified as critical due to its potential to allow unauthorized access.
What affected software is impacted by CVE-2024-10490?
CVE-2024-10490 impacts B&R mapp Cockpit, mapp View, mapp Services, mapp Motion, and mapp Vision versions prior to 6.0.
How do I fix CVE-2024-10490?
To fix CVE-2024-10490, update all affected B&R mapp products to version 6.0 or later.
What type of vulnerability is CVE-2024-10490?
CVE-2024-10490 is classified as an Authentication Bypass Using an Alternate Path or Channel vulnerability.
What could happen if CVE-2024-10490 is exploited?
If exploited, CVE-2024-10490 could allow an attacker to gain unauthorized access to the affected systems.