CVE-2023-1617: Br-Automation VC4

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this vulnerability depends on the functionality provided in the visualization. This issue affects B&R VC4: from 3.* through 3.96.7, from 4.0* through 4.06.7, from 4.1* through 4.16.3, from 4.2* through 4.26.8, from 4.3* through 4.34.6, from 4.4* through 4.45.1, from 4.5* through 4.45.3, from 4.7* through 4.72.9.

Affected products

  • Br-Automation VC4: before 3.96.8 (fixed in 3.96.8); from 4.0.0, up to and including 4.06.4; from 4.10.0, up to and including 4.16.3; from 4.20.0, up to and including 4.26.8; from 4.30.0, before 4.34.7 (fixed in 4.34.7); from 4.40.0, up to and including 4.45.1; …

Published 2023-04-14. Last modified 2026-06-17.