CVE-2021-22280

HIGH

Br-automation Automation Studio < 4.12 - Uncontrolled Search Path

Title source: rule

Description

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.

Scores

CVSS v3 7.2
EPSS 0.0008
EPSS Percentile 22.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-427 CWE-20
Status published

Affected Products (1)

br-automation/automation_studio < 4.12

Timeline

Published May 14, 2024
Tracked Since Feb 18, 2026