CVE-2019-19102

MEDIUM

B&R Automation Studio <4.2.x - Path Traversal

Title source: llm
STIX 2.1

Description

A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories. The vulnerability is also known as zip slip.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0125
EPSS Percentile 65.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
br-automation/automation_studio 4.0 - 4.0.32.15
Published Apr 29, 2020
Tracked Since Feb 18, 2026