An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Industrial_automation_aprol | Br-automation | * | r4.2-07p3 (including) |
Industrial_automation_aprol | Br-automation | r4.3-00p3 (including) | r4.4-00p3 (including) |