CVE-2019-19101: Br-Automation Automation Studio
Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade server.
Affected products
- Br-Automation Automation Studio: from 4.0, up to and including 4.0.29.87; from 4.1, up to and including 4.1.17.113; from 4.2, up to and including 4.2.14.119; from 4.3, before 4.3.11 (fixed in 4.3.11); from 4.4, before 4.4.9 (fixed in 4.4.9); from 4.5, before 4.5.5 (fixed in 4.5.5); …
Published 2020-04-29. Last modified 2026-06-17.