CVE-2021-22280
B&R Industrial Automation Studio vulnerability analysis and mitigation

Overview

CVE-2021-22280 is a security vulnerability affecting B&R Automation Studio versions 4.0 through 4.12. The vulnerability relates to improper DLL loading algorithms that could potentially allow an authenticated local attacker to execute code in the context of the product (CVE List).

Technical details

The vulnerability stems from improper DLL loading algorithms in B&R Automation Studio. This security flaw affects versions greater than or equal to 4.0 and less than 4.12 of the software. The technical nature of the vulnerability involves unsafe DLL loading mechanisms that could be exploited by an authenticated local user (CVE List).

Impact

If successfully exploited, this vulnerability allows an authenticated local attacker to execute arbitrary code in the context of the B&R Automation Studio product. This could potentially lead to unauthorized control over the affected system (CVE List).

Exploitability

The vulnerability requires local access and authentication to exploit. An attacker would need to have valid credentials and physical or remote access to the system running the vulnerable version of B&R Automation Studio (CVE List).

Mitigation and workarounds

Users should upgrade their B&R Automation Studio installation to version 4.12 or later to address this vulnerability. The upgrade will implement proper DLL loading algorithms that prevent potential code execution attacks (CVE List).

Additional resources


SourceThis report was generated using AI

Related B&R Industrial Automation Studio vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-0220HIGH8.1
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 22, 2024
CVE-2020-24682HIGH7.8
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 02, 2024
CVE-2021-22282HIGH7.8
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 02, 2024
CVE-2021-22281HIGH7.5
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesFeb 02, 2024
CVE-2021-22280HIGH7.2
  • B&R Industrial Automation Studio logoB&R Industrial Automation Studio
  • cpe:2.3:a:br-automation:automation_studio
NoYesMay 14, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management