Lucene search

K
nvd[email protected]NVD:CVE-2020-24681
HistoryFeb 02, 2024 - 7:15 a.m.

CVE-2020-24681

2024-02-0207:15:07
CWE-732
web.nvd.nist.gov
5
cve-2020-24681
b&r industrial automation
privilege escalation
resource vulnerability
permission assignment

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0

Percentile

9.0%

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP.

Affected configurations

Nvd
Node
microsoftwindowsMatch-
AND
br-automationautomation_studioRange4.04.7.7.74
OR
br-automationautomation_studioRange4.84.8.6.30
OR
br-automationautomation_studioRange4.94.9.4.92
VendorProductVersionCPE
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
br-automationautomation_studio*cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2020-24681