
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-22280 is a security vulnerability affecting B&R Automation Studio versions 4.0 through 4.12. The vulnerability relates to improper DLL loading algorithms that could potentially allow an authenticated local attacker to execute code in the context of the product (CVE List).
The vulnerability stems from improper DLL loading algorithms in B&R Automation Studio. This security flaw affects versions greater than or equal to 4.0 and less than 4.12 of the software. The technical nature of the vulnerability involves unsafe DLL loading mechanisms that could be exploited by an authenticated local user (CVE List).
If successfully exploited, this vulnerability allows an authenticated local attacker to execute arbitrary code in the context of the B&R Automation Studio product. This could potentially lead to unauthorized control over the affected system (CVE List).
The vulnerability requires local access and authentication to exploit. An attacker would need to have valid credentials and physical or remote access to the system running the vulnerable version of B&R Automation Studio (CVE List).
Users should upgrade their B&R Automation Studio installation to version 4.12 or later to address this vulnerability. The upgrade will implement proper DLL loading algorithms that prevent potential code execution attacks (CVE List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."