CVE-2024-2637 is an Uncontrolled Search Path Element vulnerability affecting numerous B&R Industrial Automation products, including Scene Viewer, Automation Runtime, and various drivers and software tools. An authenticated local attacker can exploit this by placing specially crafted files in the loading search path, leading to arbitrary code execution. With a CVSS score of 7.2 (HIGH), this vulnerability has a local attack vector and high impact on confidentiality, integrity, and availability, though it requires high attack complexity and user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| B&R Industrial Automation | ADI .NET SDK | >= 0, < 4.1.0CNA affecteddefault unaffected | |
| B&R Industrial Automation | ADI Development Kit | >= 0, < 5.5.0CNA affecteddefault unaffected | |
| B&R Industrial Automation | ADI Driver Universal | >= 0, < 3.2.0CNA affecteddefault unaffected | |
| B&R Industrial Automation | APROL | >= 0, < 4.4-01CNA affecteddefault unaffected | |
| B&R Industrial Automation | Automation Runtime | >= 0, < J4.93CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.