CVE-2020-24682: Br-Automation Automation Net/pvi
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP; NET/PVI: from 4.0 through 4.6, from 4.7.0 before 4.7.7, from 4.8.0 before 4.8.6, from 4.9.0 before 4.9.4.
Affected products
- Br-Automation Automation Net/pvi: from 4.0, before 4.7.7 (fixed in 4.7.7); from 4.8, before 4.8.6 (fixed in 4.8.6); from 4.9, before 4.9.4 (fixed in 4.9.4)
- Br-Automation Automation Studio: before 4.7.7.74 (fixed in 4.7.7.74); from 4.8, before 4.8.6.30 (fixed in 4.8.6.30); from 4.9, before 4.9.4.92 (fixed in 4.9.4.92)
Published 2024-02-02. Last modified 2026-06-17.