CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Products
B&R Industrial Automation Scene Viewer
- before 4.4.0
B&R Industrial Automation Automation Runtime
- before J4.93
B&R Industrial Automation mapp Vision
- before 5.26.1
B&R Industrial Automation mapp View
- before 5.24.2
B&R Industrial Automation mapp Cockpit
- before 5.24.2
B&R Industrial Automation mapp Safety
- before 5.24.2
B&R Industrial Automation VC4
- before 4.73.2
Source
cybersecurity@ch.abb.com
Tags
CVE-2024-2637 details
Last Modified : May 14, 2024, 7:17 p.m.
Description
An authenticated local attacker who successfully exploited this vulnerability could insert and run arbitrary code using legitimate B&R software's. An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation VC4 could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path. This issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7.2 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
CVSS Data
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
7.2
Exploitability Score
Impact Score
Base Severity
HIGH
Vector String : CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
References
URL | Source |
---|---|
https://www.br-automation.com/fileadmin/SA24P005_Insecure_Loading_of_Code-c7d9e49c.pdf | cybersecurity@ch.abb.com |