Industrial automation aprol
This hub aggregates every CVE we track for Industrial automation aprol, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
6
Critical
8
High
0
In CISA KEV
Severity distribution
HIGH8CRITICAL6MEDIUM2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Industrial automation aprol.
- CVE-2024-5624Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL6.1
- CVE-2024-5623Untrusted search path vulnerability in B&R APROL7.8
- CVE-2024-5622Untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL7.8
- CVE-2022-43765DoS in APROLs Tbase server7.5
- CVE-2022-43764Buffer overflow when changing configuration on Tbase Server9.8
- CVE-2022-43763Lack of checking preconditions in APROL 7.5
- CVE-2022-43762Memory leak when receiving messages in APROL Tbase server7.5
- CVE-2022-43761Lack of authentication when managing APROL database9.4
- CVE-2019-19878An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerabilit...7.5
- CVE-2019-19877An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks again...5.3
- CVE-2019-19876An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.9.8
- CVE-2019-19875An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and th...9.8
- CVE-2019-19874An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web serve...9.8
- CVE-2019-19873An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability tha...7.5
- CVE-2019-19872An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a...9.8
Product normalization is registry-driven with AI assist and human review. How it works