Executive brief
B&R APROL, a process control system used in industrial automation, contains a security flaw in how it verifies digital certificates. This vulnerability could allow an attacker to intercept or modify sensitive data transmitted between systems by masquerading as a trusted entity. If exploited, this could lead to the unauthorized disclosure of operational data or the manipulation of system commands, potentially impacting industrial processes.
Technical details
A vulnerability classified as Improper Certificate Validation (CWE-295) exists in B&R Industrial Automation GmbH APROL versions prior to R 4.4-01P5. The software fails to adequately validate the authenticity of digital certificates during secure communications. An unauthenticated remote attacker could exploit this by performing a man-in-the-middle (MitM) attack to intercept, decrypt, or alter encrypted traffic between the APROL system and other endpoints. While the attack requires a specific network position (High Attack Complexity), a successful exploit results in high impacts to confidentiality and integrity. Users are advised to upgrade to version R 4.4-01P5 or later.
Affected products
- B&R Industrial Automation GmbH APROL before R 4.4-01P5
Timeline
- 2026-07-06: advisory: Initial advisory published by ABB/B&R Industrial Automation
- 2026-07-06: disclosed: CVE-2026-6900 published to NVD