First published: Mon Dec 02 2024(Updated: )
An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions. B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
B&R mapp Cockpit | <6.0 | |
B&R Automation mapp View | <6.0 | |
B&R mapp Services | <6.0 | |
B&R mapp Motion | <6.0 | |
B&R mapp Vision | <6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-10490 is classified as critical due to its potential to allow unauthorized access.
CVE-2024-10490 impacts B&R mapp Cockpit, mapp View, mapp Services, mapp Motion, and mapp Vision versions prior to 6.0.
To fix CVE-2024-10490, update all affected B&R mapp products to version 6.0 or later.
CVE-2024-10490 is classified as an Authentication Bypass Using an Alternate Path or Channel vulnerability.
If exploited, CVE-2024-10490 could allow an attacker to gain unauthorized access to the affected systems.