B&R Industrial Automation
Cyber Security Advisory for B&R APROL Vulnerability
Pages
6
Time to read
9 mins
Publication
Language
English
Pages
6
Time to read
9 mins
Publication
Language
English
This document is a Cyber Security Advisory detailing a vulnerability identified in B&R APROL versions related to the SSH service, specifically concerning CVE-2023-48795. The advisory outlines the potential risks associated with a Terrapin attack, where an attacker with Man-in-the-Middle capabilities could manipulate SSH messages, compromising connection integrity. The advisory specifies the affected product versions and recommends upgrading to APROL R 4.4, as security patches for older versions have ended. It provides immediate actions for users, including disabling weak cryptographic schemes and applying updates. The advisory emphasizes B&R's commitment to user security and responsible disclosure, ensuring that customers are informed of vulnerabilities and can take appropriate measures to mitigate risks. Additionally, it includes general security recommendations to enhance system security and prevent exploitation. The advisory does not indicate any active threats at the time of publication.