CVE-2024-8313: Default or Guessable SNMP community names in B&R APROL
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration using SNMP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8313?
CVE-2024-8313 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive system information.
Who is affected by CVE-2024-8313?
CVE-2024-8313 affects the B&R APROL versions prior to 4.4-00P5.
How do I fix CVE-2024-8313?
To mitigate CVE-2024-8313, update your B&R APROL software to version 4.4-00P5 or later to close the vulnerability.
What are the potential impacts of CVE-2024-8313?
The potential impacts of CVE-2024-8313 include unauthorized access to and modification of configuration settings within the B&R APROL system.
Can CVE-2024-8313 be exploited remotely?
CVE-2024-8313 cannot be exploited remotely, as it requires an adjacent-based attacker to exploit the vulnerability.