CVE-2024-45480: B&r Industrial Automation B&r Aprol

Critical severity, CVSS 9.2. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system.

Affected products

Published 2025-03-25. Last modified 2026-06-17.