CVE-2019-19102: Br-Automation Automation Studio
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories. The vulnerability is also known as zip slip.
Affected products
- Br-Automation Automation Studio: from 4.0, up to and including 4.0.32.15; from 4.1, up to and including 4.1.17.113; from 4.2, up to and including 4.2.14.119
Published 2020-04-29. Last modified 2026-06-17.