An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions.
B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Dec 2024 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions. B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project. | |
| Title | Authentication bypass flaw in several mapp components | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ABB
Published: 2024-12-02T08:46:44.044Z
Updated: 2024-12-02T22:11:21.408Z
Reserved: 2024-10-29T11:13:34.960Z
Link: CVE-2024-10490
Updated: 2024-12-02T22:11:18.013Z
Status : Received
Published: 2024-12-02T09:15:04.613
Modified: 2024-12-02T09:15:04.613
Link: CVE-2024-10490
No data.