Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 0.36% | — | Br-automation Automation RuntimeAI | 19/1/2026 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on… | |
| Aplazada | Baja (2.3) | 0.19% | — | Br-automation RuntimeAI | 7/10/2025 | 17/6/2026 | A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions. | |
| Aplazada | Media (5.1) | 0.26% | — | Br-automation Automation RuntimeAI | 7/10/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session | |
| Aplazada | Alta (8.2) | 0.34% | — | B R Automation Mapp ViewAIBr-automation Automation RuntimeAI | 15/1/2025 | 17/6/2026 | A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices. | |
| Analizada | Media (5.1) | 0.25% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session | |
| Analizada | Media (5.4) | 0.17% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges. | |
| Analizada | Alta (7.3) | 0.17% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges. | |
| Aplazada | Media (5.3) | 0.25% | — | Br-automation Automation RuntimeAI | 12/8/2024 | 17/6/2026 | Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering. | |
| Analizada | Alta (8.3) | 0.25% | — | Br-automation Automation Runtime | 12/8/2024 | 17/6/2026 | Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication. | |
| Analizada | Alta (7.2) | 0.17% | — | Br-automation Automation Studio | 14/5/2024 | 17/6/2026 | Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Analizada | Alta (8.1) | 0.36% | — | Br-automation Automation StudioBr-automation Technology Guarding | 22/2/2024 | 17/6/2026 | B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data. | |
| Modificada | Media (6.1) | 0.37% | — | Br-automation Automation Runtime | 5/2/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session. | |
| Modificada | Crítica (9.8) | 0.23% | — | Br-automation Automation Runtime | 5/2/2024 | 17/6/2026 | The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients. | |
| Modificada | Alta (7.5) | 0.38% | — | Br-automation Automation Studio | 2/2/2024 | 17/6/2026 | : Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12. | |
| Modificada | Alta (7.8) | 0.15% | — | Br-automation Automation StudioBr-automation Automation Net/pvi | 2/2/2024 | 17/6/2026 | Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP;… | |
| Modificada | Alta (7.8) | 0.40% | — | Br-automation Automation Studio | 2/2/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12. | |
| Modificada | Alta (8.8) | 0.15% | — | Br-automation Automation Studio | 2/2/2024 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP. | |
| Modificada | Media (5.9) | 0.54% | — | Br-automation Automation Runtime | 26/7/2023 | 17/6/2026 | Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions. | |
| Modificada | Crítica (9.8) | 0.72% | — | Br-automation VC4 | 14/4/2023 | 17/6/2026 | Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this vulnerability depends on the functionality… | |
| Modificada | Media (6.1) | 0.56% | — | Br-automation Automation Runtime | 14/2/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session. | |
| Modificada | Alta (7.5) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service. | |
| Modificada | Crítica (9.8) | 0.78% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code. | |
| Modificada | Alta (7.5) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07. | |
| Modificada | Crítica (9.8) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages |