VendorsBR-Automationindustrial_automation_aprolany version
Vulnerabilities

BR-Automation Industrial Automation APROL any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2019-19875
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnerability than CVE-2019-16364.
Published 2020-11-27 · Modified
10.0EPSS 0.015
CVE-2019-19874
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.
Published 2020-11-27 · Modified
9.8EPSS 0.019
CVE-2019-19872
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-16364.
Published 2020-11-27 · Modified
9.8EPSS 0.012
CVE-2019-19876
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.
Published 2020-11-27 · Modified
9.8EPSS 0.010
CVE-2022-43764
Buffer overflow when changing configuration on Tbase Server
Published 2023-02-08 · Modified
9.8EPSS 0.008
CVE-2022-43762
Memory leak when receiving messages in APROL Tbase server
Published 2023-02-08 · Modified
9.8EPSS 0.006
CVE-2022-43761
Lack of authentication when managing APROL database
Published 2023-02-08 · Modified
9.4EPSS 0.006
CVE-2024-5622
Untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL
Published 2024-08-29 · Analyzed
7.8EPSS 0.002
CVE-2024-5623
Untrusted search path vulnerability in B&R APROL
Published 2024-08-29 · Analyzed
7.8EPSS 0.002
CVE-2019-19873
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability than CVE-2019-16356 and CVE-2019-9983.
Published 2020-11-27 · Modified
7.5EPSS 0.012
CVE-2019-19878
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358.
Published 2020-11-27 · Modified
7.5EPSS 0.012
CVE-2019-19869
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface.
Published 2020-11-27 · Modified
7.5EPSS 0.009
CVE-2022-43763
Lack of checking preconditions in APROL
Published 2023-02-08 · Modified
7.5EPSS 0.006
CVE-2022-43765
DoS in APROLs Tbase server
Published 2023-02-08 · Modified
7.5EPSS 0.006
CVE-2024-5624
Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL
Published 2024-08-29 · Analyzed
6.1EPSS 0.003
CVE-2019-19877
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against AprolSqlServer, a different vulnerability than CVE-2019-16357.
Published 2020-11-27 · Modified
5.3EPSS 0.013