« Volver al listado

CVE-2020-24681

Estado: ModificadaAlta (8.8)—

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-24681",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2020-24681",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-02T17:22:16.797450Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@ch.abb.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@ch.abb.com",
      "affectedData": [
        {
          "vendor": "B&R Industrial Automation",
          "product": "Automation Studio",
          "versions": [
            {
              "status": "affected",
              "version": "4.6.0",
              "versionType": "custom",
              "lessThanOrEqual": "4.6.x"
            },
            {
              "status": "affected",
              "version": "4.7.0",
              "lessThan": "4.7.7 SP",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.8.0",
              "lessThan": "4.8.6 SP",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.9.0",
              "lessThan": "4.9.4 SP",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "B&R Industrial Automation",
          "product": "NET/PVI",
          "versions": [
            {
              "status": "affected",
              "version": "4.6.0",
              "versionType": "custom",
              "lessThanOrEqual": "4.6.x"
            },
            {
              "status": "affected",
              "version": "4.7.0",
              "lessThan": "4.7.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.8.0",
              "lessThan": "4.8.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.9.0",
              "lessThan": "4.9.4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-02T07:15:07.333",
  "references": [
    {
      "url": "https://www.br-automation.com/fileadmin/2021-14-BR-AS-NET-PVI-Service-Issues-c3710fbf.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cybersecurity@ch.abb.com"
    },
    {
      "url": "https://www.br-automation.com/fileadmin/2021-14-BR-AS-NET-PVI-Service-Issues-c3710fbf.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@ch.abb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP.\n\n"
    },
    {
      "lang": "es",
      "value": "La asignación de permisos incorrecta para la vulnerabilidad de recursos críticos en B&R Industrial Automation Automation Studio permite la escalada de privilegios. Este problema afecta a Automation Studio: desde 4.6.0 hasta 4.6.X, desde 4.7.0 antes de 4.7.7 SP, desde 4.8.0 antes de 4.8.6 SP, desde 4.9.0 anterior a 4.9.4 SP."
    }
  ],
  "lastModified": "2026-06-17T03:05:58.557",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96888691-48DD-4173-B526-A325B8433F1B",
              "versionEndExcluding": "4.7.7.74",
              "versionStartIncluding": "4.0"
            },
            {
              "criteria": "cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04F8420B-E58C-4C17-B47B-15356571E650",
              "versionEndExcluding": "4.8.6.30",
              "versionStartIncluding": "4.8"
            },
            {
              "criteria": "cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0515B5D7-8B71-4D6E-B0E1-4E61B930A54E",
              "versionEndExcluding": "4.9.4.92",
              "versionStartIncluding": "4.9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cybersecurity@ch.abb.com"
}