
Cloud Vulnerability DB
A community-led vulnerabilities database
An authentication weakness in the SNMP service was discovered in B&R Automation Runtime affecting multiple versions including 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above. The vulnerability was disclosed in February 2020 and assigned CVE-2019-19108. This critical vulnerability affects industrial automation systems used across multiple critical infrastructure sectors including Chemical, Critical Manufacturing, and Energy sectors worldwide (CISA Advisory).
The vulnerability is classified as an Improper Authorization issue (CWE-285) with a CVSS v3.1 base score of 9.4 (Critical), and vector string AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H. The vulnerability stems from a weakness in the SNMP service implementation that allows unauthenticated access to device configuration. The issue is related to the use of hard-coded credentials (CWE-798) in the system (NVD, CISA Advisory).
Successful exploitation of this vulnerability allows remote attackers to modify the configuration of affected B&R products via SNMP without authentication. This poses significant risks to industrial control systems and critical infrastructure where these devices are deployed (CISA Advisory).
The vulnerability is considered to have low complexity for exploitation and requires no user interaction or privileges. It can be exploited remotely, though no known public exploits specifically targeting this vulnerability have been reported (CISA Advisory).
B&R has implemented mitigation measures in newer versions of Automation Studio (AS 4.6.5, AS 4.7.3, and AS 4.8.2 and higher) by disabling the SNMP service by default in newly created AS projects. Users are recommended to evaluate their need for the SNMP service and disable it if possible. Additional security measures include minimizing network exposure for control system devices, ensuring they are not accessible from the Internet, locating control system networks behind firewalls, and isolating them from business networks (CISA Advisory).
The vulnerability was discovered and reported by security researchers Yehuda Anikster and Amir Preminger of Claroty to CISA. The vendor, B&R Industrial Automation GmbH, acknowledged the issue and provided mitigation guidance through their advisory (CISA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."