CVE-2024-8314: Improper session handling in B&R APROL
An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8314?
CVE-2024-8314 is considered a high severity vulnerability due to the potential for session takeover by an authenticated attacker.
How do I fix CVE-2024-8314?
To fix CVE-2024-8314, upgrade B&R APROL to version 4.4-00P6 or later to mitigate the vulnerability.
What does CVE-2024-8314 exploit?
CVE-2024-8314 exploits an incorrect implementation of the authentication algorithm in the session handling of B&R APROL.
Who is affected by CVE-2024-8314?
Any user of B&R APROL versions earlier than 4.4-00P5 is affected by CVE-2024-8314.
Can CVE-2024-8314 be exploited remotely?
Yes, CVE-2024-8314 can be exploited by an authenticated network attacker remotely.