CVE-2024-8603
Published: 15 January 2025
Description
A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.
Security Summary
CVE-2024-8603 is a "Use of a Broken or Risky Cryptographic Algorithm" vulnerability (CWE-327) affecting the SSL/TLS component in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1. Published on 2025-01-15, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), indicating high severity due to its network accessibility, low complexity, and lack of required privileges or user interaction.
Unauthenticated network-based attackers can exploit this flaw to masquerade as services on impacted devices, enabling integrity violations such as impersonation without affecting confidentiality or availability.
B&R Automation's security advisory SA25P001, accessible at https://www.br-automation.com/fileadmin/SA25P001-c478fad6.pdf, describes the issue and recommends mitigation through upgrades to version 6.1 or later for the affected products.
Details
- CWE(s)