CVE-2020-11637: Br-Automation Automation Runtime
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.
Affected products
- Br-Automation Automation Runtime: up to and including 4.10; from 4.20, before n4.26 (fixed in n4.26); from 4.40, before f4.45 (fixed in f4.45); from 4.50, before e4.53 (fixed in e4.53); from 4.60, before d4.63 (fixed in d4.63); from 4.70, before a4.73 (fixed in a4.73); …
Published 2020-10-15. Last modified 2026-06-17.