vciy

CVEs we hold for B&r

Records whose assigning authority named B&r as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-79679Use of Weak CredentialsB&R Industrial Automation GmbH mapp Services
CVE-2026-6901Untrusted Search PathB&R Industrial Automation GmbH APROL
CVE-2026-6900Improper Certificate ValidationB&R Industrial Automation GmbH APROL
CVE-2026-0936Insertion of Sensitive Information into LogfileB&R Industrial Automation GmbH Process Visualization…
CVE-2025-3450Automation Runtime SDM requests may impact systemB&R Industrial Automation Automation Runtime
CVE-2025-3449Weak Session Token used in Automation Runtime SDMB&R Industrial Automation GmbH Automation Runtime
CVE-2025-3448XSS on SDMB&R Industrial Automation GmbH Automation Runtime
CVE-2025-11498CSV Formula Injection VulnerabilityB&R Industrial Automation GmbH Automation Runtime
CVE-2025-11482Allocation of Resources Without Limits or Throttling in the OPC-UA ServerB&R Industrial Automation GmbH PPT30 Operating System
CVE-2025-11044Vulnerability on Automation Runtime my cause DoS ConditionsB&R Industrial Automation GmbH Automation Runtime
CVE-2025-11043Improper Server Certificate Validation in Automation StudioB&R Automation Studio
CVE-2024-8603no title heldB&R Industrial Automation mapp View
CVE-2024-8315Improper Handling of Insufficient Permissions or Privileges in B&R APROLB&R APROL
CVE-2024-8314Improper session handling in B&R APROLB&R Industrial Automation GmbH APROL
CVE-2024-8313Default or Guessable SNMP community names in B&R APROLB&R Industrial Automation GmbH APROL
CVE-2024-5801IP Forwarding enabled in B&R Automation RuntimeB&R Industrial Automation Automation Runtime
CVE-2024-5800Diffie-Hellman groups with insufficient strength used in SSL/TLS stack of B&R Automation RuntimeB&R Industrial Automation Automation Runtime
CVE-2024-5624Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROLB&R APROL
CVE-2024-5623Untrusted search path vulnerability in B&R APROLB&R APROL
CVE-2024-5622Untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROLB&R APROL
CVE-2024-45484Enabled ICMP redirection in B&R APROLB&R Industrial Automation GmbH APROL
CVE-2024-45483Missing GRUB password in B&R APROLB&R Industrial Automation GmbH APROL
CVE-2024-45482Privilege escalation in B&R APROLB&R APROL
CVE-2024-45481Improper authentication in SSH of B&R APROLB&R APROL
CVE-2024-45480Unauthorized local file reading in B&R APROLB&R APROL
CVE-2024-2637Insecure Loading of Code in B&R ProductsB&R Industrial Automation KCF Editor
CVE-2024-10490Authentication bypass flaw in several mapp componentsB&R mapp Vision
CVE-2024-10210Path traversal in APROL Web PortalB&R Industrial Automation GmbH APROL
CVE-2024-10209Incorrect Permission Assignment in APROL file systemB&R Industrial Automation GmbH APROL
CVE-2024-10208Cross Site Scripting vulnerability in APROL Web PortalB&R Industrial Automation GmbH APROL
CVE-2024-10207Server-Side Request Forgery (authenticated) in APROL Web PortalB&R Industrial Automation GmbH APROL
CVE-2024-10206Server-Side Request Forgery (unauthenticated) in APROL Web PortalB&R Industrial Automation GmbH APROL
CVE-2024-0323FTP uses unsecure encryption mechanismsB&R Industrial Automation Automation Runtime
CVE-2024-0220B&R products use insufficient communication encryptionB&R Industrial Automation Technology Guarding
CVE-2023-6028SDM Web interface vulnerable to XSSB&R Industrial Automation Automation Runtime
CVE-2023-3242no title heldB&R Automation Runtime
CVE-2023-1617Improper Authentication Mechanism in B&R VC4 VisualizationB&R VC4
CVE-2022-43765DoS in APROLs Tbase serverB&R APROL
CVE-2022-43764Buffer overflow when changing configuration on Tbase ServerB&R APROL
CVE-2022-43763Lack of checking preconditions in APROLB&R APROL
CVE-2022-43762Memory leak when receiving messages in APROL Tbase serverB&R APROL
CVE-2022-43761Lack of authentication when managing APROL databaseB&R APROL
CVE-2022-4286Reflected Cross-Site Scripting Vulnerabilities in Automation RuntimeB&R Automation Runtime
CVE-2021-22289RCE through Project Upload from TargetB&R Industrial Automation Automation Studio
CVE-2021-22282RCE in B&R Automation Studio with crafted project filesB&R Industrial Automation Automation Studio
CVE-2021-22281Zip Slip Vulnerability in B&R Automation Studio Project ImportB&R Industrial Automation Automation Studio
CVE-2021-22280DLL Hijacking Vulnerability in Automation StudioB&R Industrial Automation Automation Studio
CVE-2021-22275Denial of service vulnerability on Automation Runtime webserverB&R Automation Automation Runtime webserver
CVE-2020-24682Automation Studio and PVI Multiple unquoted service path vulnerabilitiesB&R Industrial Automation NET/PVI
CVE-2020-24681Automation Studio and PVI Multiple incorrect permission assignments for servicesB&R Industrial Automation NET/PVI
CVE-2020-11646GateManager Log Information Disclosure VulnerabilityB&R GateManager
CVE-2020-11645GateManager Denial of Service VulnerabilityB&R GateManager
CVE-2020-11644GateManager Audit Message Spoofing VulnerabilityB&R GateManager
CVE-2020-11643GateManager Information Disclosure VulnerabilityB&R GateManager
CVE-2020-11642SiteManager Denial of Service via Local File Inclusion VulnerabilityB&R SiteManager
CVE-2020-11641SiteManager Local File Inclusion VulnerabilityB&R SiteManager
CVE-2020-11637Automation Runtime TFTP Service DoS VulnerabilityB&R Automation Runtime
CVE-2019-19108B&R Automation Runtime SNMP Authentication and Authorization WeaknessB&R Automation Runtime
CVE-2019-19102Zip Slip vulnerability in 3rd-Party library in B&R Automation Studio upgrade serviceB&R Automation Studio
CVE-2019-19101Incomplete communication encryption and validation in B&R Automation Studio upgrade serviceB&R Automation Studio
CVE-2019-19100Privilege escalation via B&R Automation Studio upgrade serviceB&R Automation Studio

61 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.