We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-0323

FTP uses unsecure encryption mechanisms



AssignerABB
Reserved2024-01-08
Published2024-02-05
Updated2024-09-06

Description

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.



CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-1240: Use of a Cryptographic Primitive with a Risky Implementation

Product status

Default status
0x40033a29d0

14.0 before 14.93
affected

References

https://www.br-automation.com/fileadmin/SA23P004_FTP_uses_unsecure_encryption_mechanisms-f57c147c.pdf

cve.org CVE-2024-0323

nvd.nist.gov CVE-2024-0323

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-0323
Subscribe to our newsletter to learn more about our work.