An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions.
B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Dec 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 02 Dec 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions. B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project. | |
Title | Authentication bypass flaw in several mapp components | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-12-02T22:11:21.408Z
Reserved: 2024-10-29T11:13:34.960Z
Link: CVE-2024-10490

Updated: 2024-12-02T22:11:18.013Z

Status : Received
Published: 2024-12-02T09:15:04.613
Modified: 2024-12-02T09:15:04.613
Link: CVE-2024-10490

No data.