CVE-2024-8603

HIGH

B&R Automation Runtime <6.1, B&R mapp View <6.1 - Use After Free

Title source: llm
STIX 2.1

Description

A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 18.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-327
Status published
Products (4)
B&R Industrial Automation/Automation Runtime 4.0
B&R Industrial Automation/Automation Runtime 6.0 - 6.1
B&R Industrial Automation/mapp View 5.0
B&R Industrial Automation/mapp View 6.0 - 6.1
Published Jan 15, 2025
Tracked Since Feb 18, 2026