An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.
The product contains hard-coded credentials, such as a password or cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Automation_runtime | Br-automation | 3.08 (including) | 3.10 (including) |
Automation_runtime | Br-automation | 4.00 (including) | 4.03 (including) |
Automation_runtime | Br-automation | 4.04 (including) | 4.63 (including) |
Automation_runtime | Br-automation | 2.96 (including) | 2.96 (including) |
Automation_runtime | Br-automation | 3.00 (including) | 3.00 (including) |
Automation_runtime | Br-automation | 3.01 (including) | 3.01 (including) |
Automation_runtime | Br-automation | 3.06 (including) | 3.06 (including) |
Automation_runtime | Br-automation | 3.07 (including) | 3.07 (including) |
Automation_runtime | Br-automation | 4.72 (including) | 4.72 (including) |
Automation_studio | Br-automation | 4.0.0 (including) | 4.6.4 (including) |
Automation_studio | Br-automation | 2.7 (including) | 2.7 (including) |
Automation_studio | Br-automation | 3.0.71 (including) | 3.0.71 (including) |
Automation_studio | Br-automation | 3.0.80 (including) | 3.0.80 (including) |
Automation_studio | Br-automation | 3.0.81 (including) | 3.0.81 (including) |
Automation_studio | Br-automation | 3.0.90 (including) | 3.0.90 (including) |
Automation_studio | Br-automation | 4.7.2 (including) | 4.7.2 (including) |
There are two main variations: