CVE-2019-19108: Br-Automation Automation Runtime

Critical severity, CVSS 9.4. EPSS: 1.6% chance of exploitation in the next 30 days.

An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.

Affected products

  • Br-Automation Automation Runtime: from 3.08, up to and including 3.10; from 4.00, up to and including 4.03; from 4.04, up to and including 4.63; version 2.96 only; version 3.00 only; version 3.01 only; …
  • Br-Automation Automation Studio: from 4.0.0, up to and including 4.6.4; version 2.7 only; version 3.0.71 only; version 3.0.80 only; version 3.0.81 only; version 3.0.90 only; …

Published 2020-04-20. Last modified 2026-06-17.