AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›B&R Automation
B&
Platform

B&R Automation

PC-based industrial automation with Automation Studio IEC 61131-3, X20/X90 I/O, and APROL process control.

https://www.br-automation.com →
20
Total CVEs
0
Resources
3
CRIT
7
HIGH
9
MED
0
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
9 / 20
CVE-2025-11044MEDIUM

An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on affected devices.

Jan 19, 2026
6.8
CVE-2019-19101MEDIUM

A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade server.

Apr 29, 2020
6.5
CVE-2025-11498MEDIUM

An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a malicious link. The user would need to click on this link, after which the resulting CSV file addi-tionally needs to be manually opened.

Oct 14, 2025
6.1
CVE-2025-3448MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session

Oct 7, 2025
6.1
CVE-2023-6028MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.

Feb 5, 2024
6.1
CVE-2022-4286MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.

Feb 14, 2023
6.1
CVE-2020-11637MEDIUM

A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.

Oct 15, 2020
5.8
CVE-2019-19102MEDIUM

A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories. The vulnerability is also known as zip slip.

Apr 29, 2020
5.5
CVE-2025-3449MEDIUM

A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions.

Oct 7, 2025
4.2
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2025-11044MEDIUM
6.8
An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component o…Jan 19, 2026›
CVE-2019-19101MEDIUM
6.5
A missing secure communication definition and an incomplete TLS validation in the upgrade service in…Apr 29, 2020›
CVE-2025-11498MEDIUM
6.1
An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnost…Oct 14, 2025›
CVE-2025-3448MEDIUM
6.1
Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&…Oct 7, 2025›
CVE-2023-6028MEDIUM
6.1
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics…Feb 5, 2024›
CVE-2022-4286MEDIUM
6.1
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Au…Feb 14, 2023›
CVE-2020-11637MEDIUM
5.8
A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53,…Oct 15, 2020›
CVE-2019-19102MEDIUM
5.5
A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Stu…Apr 29, 2020›
CVE-2025-3449MEDIUM
4.2
A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automat…Oct 7, 2025›