Cyber Posture

CVE-2024-8603

High

Published: 15 January 2025

Published
15 January 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.0006 18.5th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.

Security Summary

CVE-2024-8603 is a "Use of a Broken or Risky Cryptographic Algorithm" vulnerability (CWE-327) affecting the SSL/TLS component in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1. Published on 2025-01-15, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), indicating high severity due to its network accessibility, low complexity, and lack of required privileges or user interaction.

Unauthenticated network-based attackers can exploit this flaw to masquerade as services on impacted devices, enabling integrity violations such as impersonation without affecting confidentiality or availability.

B&R Automation's security advisory SA25P001, accessible at https://www.br-automation.com/fileadmin/SA25P001-c478fad6.pdf, describes the issue and recommends mitigation through upgrades to version 6.1 or later for the affected products.

Details

CWE(s)
CWE-327

References