Use of a Broken or Risky Cryptographic Algorithm...
Critical severity
Unreviewed
Published
Feb 5, 2024
to the GitHub Advisory Database
•
Updated Sep 6, 2024
Description
Published by the National Vulnerability Database
Feb 5, 2024
Published to the GitHub Advisory Database
Feb 5, 2024
Last updated
Sep 6, 2024
Use of a Broken or Risky Cryptographic Algorithm vulnerability in B&R Industrial Automation Automation Runtime (SDM modules).
The FTP server used on the B&R
Automation Runtime supports unsecure encryption mechanisms, such as SSLv3,
TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct
man-in-the-middle attacks or to decrypt communications between the affected product
clients.
This issue affects Automation Runtime: from 14.0 before 14.93.
References