CVE-2024-45483: Missing GRUB password in B&R APROL
A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical attacker to alter the boot configuration of the operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45483?
CVE-2024-45483 is considered a high severity vulnerability due to its potential to allow unauthenticated physical access to critical boot configuration settings.
How do I fix CVE-2024-45483?
To fix CVE-2024-45483, update B&R APROL to version 4.4-01 or later to ensure proper authentication mechanisms are in place.
What impact does CVE-2024-45483 have on system security?
CVE-2024-45483 can lead to unauthorized changes in the operating system's boot configuration, compromising the overall security of the system.
Who is affected by CVE-2024-45483?
CVE-2024-45483 affects users of B&R APROL versions prior to 4.4-01.
Can CVE-2024-45483 be exploited remotely?
CVE-2024-45483 requires physical access to the system to be exploited, making it a localized risk rather than a remote threat.