The vendor explicitly identifies these products as affected by this CVE.
- B&R Industrial Automation GmbH APC4100 <1.09
- B&R Industrial Automation GmbH APC910 <=1.25
- B&R Industrial Automation GmbH C80 <1.14
- B&R Industrial Automation GmbH MPC3100 <1.24
- B&R Industrial Automation GmbH PPC1200 <1.14
- B&R Industrial Automation GmbH PPC900 <2.16
- B&R Industrial Automation GmbH APC2200 <1.35
- B&R Industrial Automation GmbH PPC2200 <1.35
- B&R Industrial Automation GmbH APC3100 <1.45
- B&R Industrial Automation GmbH PPC3100 <1.45
- Summary
- EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
- Remediation
- The problems are corrected in the following product versions: - APC4100 1.09 - APC910 No patch will be released (Please refer to the mitigation measures specified in this advisory). - C80 1.14 - MPC3100 1.24 - PPC1200 1.14 - PPC900 2.16 - APC2200 1.35 - PPC2200 1.35 - APC3100 1.45 - PPC3100 1.45 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
