PT-2024-37164 · Br · B&R Automation Runtime

CVE-2024-5800

·

Published

2024-08-10

·

Updated

2024-08-12

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: B&R Automation Runtime versions prior to 6.0.2
Description: The issue concerns the use of Diffie-Hellman groups with insufficient strength in the SSL/TLS stack, allowing a network attacker to decrypt the SSL/TLS communication.
Recommendations: For versions prior to 6.0.2, update to version 6.0.2 or later to resolve the issue.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5800

Affected Products

B&R Automation Runtime