The vendor explicitly identifies these products as affected by this CVE.
- B&R Industrial Automation GmbH APROL <R 4.4-01P5
- Summary
- An Untrusted Search Path vulnerability in the webserver used in APROL version prior to R 4.4-01P5 may allow authenticated local attackers to elevate their privileges.
- Remediation
- The problem is corrected in the following product versions: - APROL >= R 4.4-01P5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
