We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-0323

FTP uses unsecure encryption mechanisms



Description

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.

Reserved 2024-01-08 | Published 2024-02-05 | Updated 2024-09-06 | Assigner ABB


CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-1240: Use of a Cryptographic Primitive with a Risky Implementation

Product status

Default status
unaffected

14.0 before 14.93
affected

References

www.br-automation.com/..._encryption_mechanisms-f57c147c.pdf

cve.org (CVE-2024-0323)

nvd.nist.gov (CVE-2024-0323)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-0323

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.