B&R APROL
cpe:2.3:a:br-automation:industrial_automation_aprol:*:*:*:*:*:*:*
- < 4.4-01
- >= 4.4-00P1, <= 4.4-00P5
A server-side request forgery (SSRF) vulnerability has been identified in the APROL Web Portal, specifically in B&R APROL versions prior to 4.4-00P5. This vulnerability allows an authenticated network-based attacker to manipulate the web server into making requests to arbitrary URLs.
Exploitation of this vulnerability could lead to server-side request forgery, allowing attackers to make unauthorized requests from the server.
Users are advised to upgrade to B&R APROL version 4.4-01 or version 4.4-00P5 or later. After applying the update, it is recommended to change all passwords and secrets, as some vulnerabilities may have compromised credential confidentiality.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.