CVE-2024-0220
Estado: AnalizadaAlta (8.1)—
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 28
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-94, CWE-319, CWE-1240
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-0220",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-0220",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-02-22T16:23:26.378691Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@ch.abb.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.3,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cybersecurity@ch.abb.com",
"affectedData": [
{
"vendor": "B&R Industrial Automation",
"modules": [
"Upgrade Service"
],
"product": "Automation Studio",
"versions": [
{
"status": "affected",
"version": "4.0",
"lessThan": "4.6",
"versionType": "patch"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "B&R Industrial Automation",
"product": "Technology Guarding",
"versions": [
{
"status": "affected",
"version": "1.0.0",
"lessThan": "1.4.0",
"versionType": "patch"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*"
],
"vendor": "br-automation",
"product": "automation_studio",
"versions": [
{
"status": "affected",
"version": "4.0",
"lessThan": "4.6",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-02-22T11:15:08.840",
"references": [
{
"url": "https://www.br-automation.com/fileadmin/SA23P019_Automation_Studio_Upgrade_Service_uses_insufficient_encryption.pdf-1b3b181c.pdf",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@ch.abb.com"
},
{
"url": "https://www.br-automation.com/fileadmin/SA23P019_Automation_Studio_Upgrade_Service_uses_insufficient_encryption.pdf-1b3b181c.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@ch.abb.com",
"description": [
{
"lang": "en",
"value": "CWE-94"
},
{
"lang": "en",
"value": "CWE-319"
},
{
"lang": "en",
"value": "CWE-1240"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data."
},
{
"lang": "es",
"value": "B&R Automation Studio Upgrade Service y B&R Technology Guarding utilizan criptografía insuficiente para la comunicación con la actualización y los servidores de licencias. Un atacante basado en la red podría aprovechar la vulnerabilidad para ejecutar código arbitrario en los productos o rastrear datos confidenciales. Falta de cifrado de datos confidenciales, transmisión de texto plano de información confidencial, control inadecuado de la generación de código (\"inyección de código\"), vulnerabilidad de fuerza de cifrado inadecuada en B&R Industrial Automation B&R Automation Studio (módulos de servicio de actualización), B&R Industrial Automation Technology Guarding.Este problema afecta a B&R Automation Studio: <4,6; Protección de tecnología: <1.4.0."
}
],
"lastModified": "2026-06-17T06:53:01.413",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD356F7B-A7B5-4D27-B270-4C2174C29985",
"versionEndExcluding": "4.6"
},
{
"criteria": "cpe:2.3:a:br-automation:technology_guarding:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61EBB91B-EFA1-4D6F-8121-A665EBF25D91",
"versionEndExcluding": "1.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cybersecurity@ch.abb.com"
}