The vendor explicitly identifies these products as affected by this CVE.
- B&R Industrial Automation GmbH mapp Audit installed with mapp Services <6.8.0
- Summary
- A vulnerability in mapp Audit in B&R mapp Services before version 6.8.0 is caused by insufficient entropy of the authenticators, which could allow an attacker with network access to gain access to the OPC UA server functionality used by mapp Audit.
- Remediation
- The problem is corrected in the following product versions: mapp Services >= 6.8.0 B&R recommends that customers apply the update at earliest convenience when the vulnerable functionality mapp Audit is used. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
