Q2BSTUDIO is a technology development and services company. View CSAF
The CVSS v4 is 9.2
ATTENTION: Exploitable remotely / Low attack complexity
Vendor: B&R
Equipment: APROL
Vulnerabilities: Inclusion of Untrusted Control Sphere Functionality, Incomplete Filtering of Special Elements, Inadequate Control of Code Generation ('Code Injection'), Inadequate Handling of Permissions or Insufficient Privileges, Unbounded or Regulated Resource Allocation, Missing Authentication for Critical Function, Exposure of Sensitive System Information to an Unauthorized Control Sphere, Exposure of Data Element to Wrong Session, Server-Side Request Forgery (SSRF), Incorrect Neutralization of Input During Web Page Generation ('Cross-site Scripting'), External Control of File Name or Path, Incorrect Permission Assignment for Critical Resource
Successful exploitation of these vulnerabilities could allow an attacker to execute commands, elevate privileges, gather sensitive information, or alter the product.
B&R has identified the following APROL and APROL-correlative Work Methods:
APROL Version 4.4-01: B&R recommends that users apply the patch or upgrade to a non-vulnerable version as soon as possible.
APROL Version 4.4-00P1: B&R recommends that users apply the patch or upgrade to a non-vulnerable version as soon as possible.
APROL Version 4.4-00P5: B&R recommends that users apply the patch or upgrade to a non-vulnerable version as soon as possible.
For more information, refer to B&R's security advisory.
No specific public exploits targeting these vulnerabilities have been reported to date.
April 3, 2025: Initial publication of B&R SA24P015





