The vendor explicitly identifies these products as affected by this CVE.
- B&R Industrial Automation GmbH APROL <R 4.4-01P5
- Summary
- An Improper Certificate Validation vulnerability in the LDAP Server Connector used in APROL version prior to R 4.4-01P5 may allow network-based attackers to conduct adversary -in-the-middle attacks causing information disclosure or identity spoofing.
- Remediation
- The problem is corrected in the following product versions: - APROL >= R 4.4-01P5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
