A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Automation_runtime | Br-automation | * | 4.10 (including) |
Automation_runtime | Br-automation | 4.20 (including) | n4.26 (excluding) |
Automation_runtime | Br-automation | 4.40 (including) | f4.45 (excluding) |
Automation_runtime | Br-automation | 4.50 (including) | e4.53 (excluding) |
Automation_runtime | Br-automation | 4.60 (including) | d4.63 (excluding) |
Automation_runtime | Br-automation | 4.70 (including) | a4.73 (excluding) |