Automation Runtime supports unsecure encryption mechanisms, such as SSLv3,
TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct
man-in-the-middle attacks or to decrypt communications between the affected product
clients.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16119 | The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients. |
Fri, 06 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-327 |
Fri, 06 Sep 2024 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1240 |
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-09-06T07:21:29.270Z
Reserved: 2024-01-08T13:02:23.041Z
Link: CVE-2024-0323
Updated: 2024-08-01T18:04:49.140Z
Status : Modified
Published: 2024-02-05T16:15:54.980
Modified: 2024-11-21T08:46:19.440
Link: CVE-2024-0323
No data.
OpenCVE Enrichment
No data.
EUVD