Vulnerability Details CVE-2024-5623
An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.1%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2024-5623
-
cpe:2.3:a:br-automation:industrial_automation_aprol:-
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-01
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-03
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-05
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-07
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.2-07p3
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.3-00p3
-
cpe:2.3:a:br-automation:industrial_automation_aprol:r4.4-00p3