漏洞描述 B&R Automation Runtime是B&R Automation公司的一个自动化运行时。 B&R Automation Runtime 6.1之前版本和B&R mapp View 6.1之前版本存在加密问题漏洞,该漏洞源于使用损坏或有风险的加密算法。
相关漏洞推荐 POC CVE-2021-41291: ECOA Building Automation System - Directory Traversal Content Disclosure POC CVE-2021-41293: ECOA Building Automation System - Arbitrary File Retrieval POC CVE-2022-22972: VMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication Bypass POC CVE-2022-26833: Open Automation Software OAS Platform V16.00.0121 - Missing Authentication POC CVE-2024-6922: Automation Anywhere Automation 360 - Server-Side Request Forgery POC CVE-2024-9186: Automation By Autonami < 3.3.0 - SQL Injection POC CVE-2025-1562: Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control POC CVE-2025-3102: SureTriggers – All-in-One Automation Platform ≤ 1.0.78 - Authentication Bypass POC gcloud-func-auto-runtime-updates-disabled: Automatic Runtime Security Updates Disabled in Google Cloud Functions POC CVE-2020-21998: HomeAutomation 3.3.2 - Open Redirect POC tcpconfig: Rockwell Automation TCP/IP Configuration Information - Detect IBM Cloud Pak for Business Automation 跨站脚本漏洞 IBM Robotic Process Automation 跨站脚本漏洞