CVE-2024-5622: Untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL
An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5622?
CVE-2024-5622 has a high severity rating due to its potential for allowing authenticated local attackers to execute arbitrary code with elevated privileges.
How do I fix CVE-2024-5622?
To mitigate CVE-2024-5622, upgrade to a patched version of B&R APROL beyond R 4.2-07P3 and R 4.4-00P3.
Who is affected by CVE-2024-5622?
CVE-2024-5622 affects users of B&R APROL versions R 4.2-07P3 and R 4.4-00P3.
What is an untrusted search path vulnerability in CVE-2024-5622?
An untrusted search path vulnerability allows an attacker to execute malicious code by using a manipulated search path during application execution.
Is authentication required to exploit CVE-2024-5622?
Yes, CVE-2024-5622 requires that the attacker is authenticated as a local user to execute the attack.