Vulnerability Details CVE-2024-5623
An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.8%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2024-5623
-
cpe:2.3:a:br-automation:industrial_automation_aprol:-
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-01
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-03
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-05
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-07
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-07p3
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.3-00p3
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.4-00p3