PT-2023-1648 · B&R · B&R Aprol

CVE-2022-43764

·

Published

2023-02-08

·

Updated

2023-02-18

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions B&R APROL versions prior to R 4.2-07
Description The issue is related to insufficient validation of input parameters when changing configuration on the Tbase server, which could result in a buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code. The vulnerability can be exploited remotely.
Recommendations For versions prior to R 4.2-07, update to version R 4.2-07 or later to resolve the issue. As a temporary workaround, consider restricting access to the Tbase server configuration to minimize the risk of exploitation.

Fix

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01184
CVE-2022-43764

Affected Products

B&R Aprol