{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "tracking": {
      "generator": {
        "date": "2025-03-24T08:22:36.527Z",
        "engine": {
          "version": "2.5.21",
          "name": "Secvisogram"
        }
      },
      "current_release_date": "2025-03-24T00:30:00.000Z",
      "initial_release_date": "2025-03-24T00:30:00.000Z",
      "id": "SA24P015",
      "status": "final",
      "version": "1.0.0",
      "revision_history": [
        {
          "date": "2025-03-24T00:30:00.000Z",
          "number": "1.0.0",
          "summary": "Initial version."
        }
      ]
    },
    "notes": [
      {
        "category": "summary",
        "text": "Updates are available that resolve privately reported vulnerabilities in the product versions listed as affected in this advisory.\n\nAn attacker who successfully exploits these vulnerabilities could elevate privileges or gather sensitive information.\n\n\n",
        "title": "Summary"
      },
      {
        "title": "Mitigating factors",
        "category": "general",
        "text": "Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. Please refer to “General security recommendations” to get general guidelines how to mitigate threats on IACS. \nB&R can support customers with various measures to mitigate the listed vulnerabilities. Please contact APROL Support for assistance.\n"
      },
      {
        "category": "other",
        "text": "For any installation of software-related B&R products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n–\tIsolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general-purpose network (e.g. office or home networks).\n–\tInstall physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n–\tNever connect programming software or computers containing programing software to any net-work other than the network for the devices that it is intended for.\n–\tScan all data imported into your environment before use to detect potential malware infections.\n–\tMinimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n–\tEnsure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n–\tWhen remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\nMore information on recommended practices can be found in the following documents:(Defense in Depth for B&R products)\n",
        "title": "General security recommendations"
      },
      {
        "text": "The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\nAll rights to registrations and trademarks reside with their respective owners.\n",
        "category": "legal_disclaimer",
        "title": "Notice"
      },
      {
        "text": "For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n",
        "title": "Support",
        "category": "other"
      }
    ],
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "publisher": {
      "category": "vendor",
      "name": "ABB PSIRT",
      "namespace": "https://global.abb/group/en/technology/cyber-security/alerts-and-notifications"
    },
    "references": [
      {
        "summary": "B&R Advisory Link",
        "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf"
      },
      {
        "url": "https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf",
        "summary": "Recommended practices can be found in the following documents: Defense in Depth for B&R products "
      }
    ],
    "lang": "en",
    "title": "B&R APROL Potential Privilege Escalation and Information Disclosure"
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "B&R",
        "branches": [
          {
            "category": "product_name",
            "name": "B&R APROL",
            "branches": [
              {
                "category": "product_version_range",
                "name": "<4.4-01",
                "product": {
                  "name": "B&R APROL < 4.4-01",
                  "product_id": "AV1"
                }
              },
              {
                "category": "product_version",
                "name": "4.4-01",
                "product": {
                  "name": "B&R APROL 4.4-01",
                  "product_id": "FX1"
                }
              },
              {
                "category": "product_version_range",
                "name": ">=4.4-00P1",
                "product": {
                  "name": "B&R APROL >= 4.4-00P1",
                  "product_id": "FX2"
                }
              },
              {
                "category": "product_version_range",
                "product": {
                  "name": "B&R APROL < 4.4-00P1",
                  "product_id": "AV2"
                },
                "name": "<4.4-00P1"
              },
              {
                "category": "product_version_range",
                "name": ">=4.4-00P5",
                "product": {
                  "name": "B&R APROL >= 4.4-00P5",
                  "product_id": "FX3"
                }
              },
              {
                "category": "product_version_range",
                "name": "< 4.4-00P5",
                "product": {
                  "name": "B&R APROL < 4.4-00P5",
                  "product_id": "AV3"
                }
              }
            ]
          }
        ]
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-45482",
      "title": "CVE-2024-45482",
      "cwe": {
        "id": "CWE-829",
        "name": "Inclusion of Functionality from Untrusted Control Sphere"
      },
      "notes": [
        {
          "text": "An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an authenticated local attacker from a trusted remote server to execute malicious commands.",
          "category": "description",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "FX2"
        ],
        "known_affected": [
          "AV2"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "NVD - CVE-2024-45482",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45482"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          },
          "products": [
            "AV2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-45481",
      "title": "CVE-2024-45481",
      "cwe": {
        "id": "CWE-791",
        "name": "Incomplete Filtering of Special Elements"
      },
      "notes": [
        {
          "category": "description",
          "title": "description",
          "text": "An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may allow an authenticated local attacker to authenticate as another legitimate user."
        }
      ],
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "NVD - CVE-2024-45481",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45481"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          },
          "products": [
            "AV3"
          ]
        }
      ]
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system."
        }
      ],
      "references": [
        {
          "category": "self",
          "summary": "NVD - CVE-2024-45480",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45480"
        }
      ],
      "cve": "CVE-2024-45480",
      "title": "CVE-2024-45480",
      "remediations": [
        {
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "category": "vendor_fix",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "cwe": {
        "id": "CWE-94",
        "name": "Improper Control of Generation of Code ('Code Injection')"
      },
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:F/RL:O/RC:C",
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "temporalScore": 8,
            "temporalSeverity": "HIGH",
            "environmentalScore": 8,
            "environmentalSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "CHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          },
          "products": [
            "AV3"
          ]
        }
      ]
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential information."
        }
      ],
      "references": [
        {
          "category": "self",
          "summary": "NVD - CVE-2024-8315",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8315"
        }
      ],
      "cve": "CVE-2024-8315",
      "title": "CVE-2024-8315",
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "cwe": {
        "id": "CWE-280",
        "name": "Improper Handling of Insufficient Permissions or Privileges "
      },
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "temporalScore": 5.1,
            "temporalSeverity": "MEDIUM",
            "environmentalScore": 5.1,
            "environmentalSeverity": "MEDIUM",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          },
          "products": [
            "AV3"
          ]
        }
      ]
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL <4.4-00P5 may allow an unauthenticated adjacent attacker to per-form Denial-of-Service (DoS) attacks against the product."
        }
      ],
      "references": [
        {
          "summary": "NVD - CVE-2024-45484",
          "category": "self",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45484"
        }
      ],
      "cve": "CVE-2024-45484",
      "title": "CVE-2024-45484",
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "product_status": {
        "known_affected": [
          "AV3"
        ],
        "fixed": [
          "FX3"
        ]
      },
      "scores": [
        {
          "products": [
            "AV3"
          ],
          "cvss_v3": {
            "version": "3.1",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "availabilityImpact": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H/E:F/RL:O/RC:C",
            "baseScore": 7.6,
            "baseSeverity": "HIGH",
            "temporalScore": 7.1,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.1,
            "environmentalSeverity": "HIGH"
          }
        }
      ]
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical attacker to alter the boot configuration of the operating system."
        }
      ],
      "references": [
        {
          "category": "self",
          "summary": "NVD - CVE-2024-45483",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45483"
        }
      ],
      "cve": "CVE-2024-45483",
      "title": "CVE-2024-45483",
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV1"
          ]
        }
      ],
      "cwe": {
        "id": "CWE-306",
        "name": "Missing Authentication for Critical Function"
      },
      "product_status": {
        "fixed": [
          "FX1"
        ],
        "known_affected": [
          "AV1"
        ]
      },
      "scores": [
        {
          "products": [
            "AV1"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "temporalScore": 6.3,
            "temporalSeverity": "MEDIUM",
            "environmentalScore": 6.3,
            "environmentalSeverity": "MEDIUM",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          }
        }
      ]
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration using SNMP. "
        }
      ],
      "cve": "CVE-2024-8313",
      "title": "CVE-2024-8313",
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8313",
          "summary": "NVD - CVE-2024-8313",
          "category": "self"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "products": [
            "AV3"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "temporalScore": 8.2,
            "temporalSeverity": "HIGH",
            "environmentalScore": 8.2,
            "environmentalSeverity": "HIGH",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          }
        }
      ],
      "cwe": {
        "id": "CWE-497",
        "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere"
      }
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Session vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials."
        }
      ],
      "cve": "CVE-2024-8314",
      "title": "CVE-2024-8314",
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8314",
          "summary": "NVD - CVE-2024-8314",
          "category": "self"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C",
            "baseScore": 8,
            "baseSeverity": "HIGH",
            "temporalScore": 7.4,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "scope": "CHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          },
          "products": [
            "AV3"
          ]
        }
      ],
      "cwe": {
        "id": "CWE-488",
        "name": "Exposure of Data Element to Wrong Session"
      }
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs."
        }
      ],
      "cve": "CVE-2024-10206",
      "title": "CVE-2024-10206",
      "references": [
        {
          "category": "self",
          "summary": "NVD - CVE-2024-10206",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10206"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "products": [
            "AV3"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "temporalScore": 4.9,
            "temporalSeverity": "MEDIUM",
            "environmentalScore": 4.9,
            "environmentalSeverity": "MEDIUM",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          }
        }
      ],
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      }
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to force the web server to request arbitrary URLs"
        }
      ],
      "cve": "CVE-2024-10207",
      "title": "CVE-2024-10207",
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10207",
          "summary": "NVD - CVE-2024-10207",
          "category": "self"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "products": [
            "AV3"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "temporalScore": 4,
            "temporalSeverity": "MEDIUM",
            "environmentalScore": 4,
            "environmentalSeverity": "MEDIUM",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          }
        }
      ],
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      }
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session."
        }
      ],
      "cve": "CVE-2024-10208",
      "title": "CVE-2024-10208",
      "references": [
        {
          "summary": "NVD - CVE-2024-10208",
          "category": "self",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10208"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "products": [
            "AV3"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "temporalScore": 5.7,
            "temporalSeverity": "MEDIUM",
            "environmentalScore": 5.7,
            "environmentalSeverity": "MEDIUM",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "scope": "CHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "availabilityImpact": "NONE",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          }
        }
      ],
      "cwe": {
        "id": "CWE-79",
        "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
      }
    },
    {
      "notes": [
        {
          "title": "CVE Description",
          "category": "description",
          "text": "An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker to access data from the file system."
        }
      ],
      "cve": "CVE-2024-10210",
      "title": "CVE-2024-10210",
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10210",
          "summary": "NVD - CVE-2024-10210",
          "category": "self"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV3"
          ]
        }
      ],
      "cwe": {
        "id": "CWE-73",
        "name": "External Control of File Name or Path"
      },
      "product_status": {
        "fixed": [
          "FX3"
        ],
        "known_affected": [
          "AV3"
        ]
      },
      "scores": [
        {
          "products": [
            "AV3"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N/E:F/RL:O/RC:C",
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "temporalScore": 7.9,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.9,
            "environmentalSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "CHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "availabilityImpact": "NONE",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          }
        }
      ]
    },
    {
      "cve": "CVE-2024-10209",
      "title": "CVE-2024-10209",
      "cwe": {
        "id": "CWE-732",
        "name": "Incorrect Permission Assignment for Critical Resource"
      },
      "notes": [
        {
          "category": "description",
          "title": "CVE Description",
          "text": "An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user."
        }
      ],
      "product_status": {
        "known_affected": [
          "AV1"
        ],
        "fixed": [
          "FX1"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "NVD - CVE-2024-10209",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10209"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "B&R recommends that customers apply the patch or upgrade to a non-vulnerable version at their earliest convenience.\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\nAs some of the vulnerabilities affect the confidentiality of credentials, it is recommended to change all secrets/passwords after applying the update.\n",
          "product_ids": [
            "AV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED"
          },
          "products": [
            "AV1"
          ]
        }
      ]
    }
  ]
}