CVE-2019-19108
B&R Industrial Automation Studio vulnerability analysis and mitigation

Overview

An authentication weakness in the SNMP service was discovered in B&R Automation Runtime affecting multiple versions including 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above. The vulnerability was disclosed in February 2020 and assigned CVE-2019-19108. This critical vulnerability affects industrial automation systems used across multiple critical infrastructure sectors including Chemical, Critical Manufacturing, and Energy sectors worldwide (CISA Advisory).

Technical details

The vulnerability is classified as an Improper Authorization issue (CWE-285) with a CVSS v3.1 base score of 9.4 (Critical), and vector string AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H. The vulnerability stems from a weakness in the SNMP service implementation that allows unauthenticated access to device configuration. The issue is related to the use of hard-coded credentials (CWE-798) in the system (NVD, CISA Advisory).

Impact

Successful exploitation of this vulnerability allows remote attackers to modify the configuration of affected B&R products via SNMP without authentication. This poses significant risks to industrial control systems and critical infrastructure where these devices are deployed (CISA Advisory).

Exploitability

The vulnerability is considered to have low complexity for exploitation and requires no user interaction or privileges. It can be exploited remotely, though no known public exploits specifically targeting this vulnerability have been reported (CISA Advisory).

Mitigation and workarounds

B&R has implemented mitigation measures in newer versions of Automation Studio (AS 4.6.5, AS 4.7.3, and AS 4.8.2 and higher) by disabling the SNMP service by default in newly created AS projects. Users are recommended to evaluate their need for the SNMP service and disable it if possible. Additional security measures include minimizing network exposure for control system devices, ensuring they are not accessible from the Internet, locating control system networks behind firewalls, and isolating them from business networks (CISA Advisory).

Community reactions

The vulnerability was discovered and reported by security researchers Yehuda Anikster and Amir Preminger of Claroty to CISA. The vendor, B&R Industrial Automation GmbH, acknowledged the issue and provided mitigation guidance through their advisory (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related B&R Industrial Automation Studio vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-0220HIGH8.1
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 22, 2024
CVE-2020-24682HIGH7.8
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 02, 2024
CVE-2021-22282HIGH7.8
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 02, 2024
CVE-2021-22281HIGH7.5
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 02, 2024
CVE-2021-22280HIGH7.2
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesMay 14, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management