Executive brief
B&R APROL, a process control system used in industrial automation, is affected by a security flaw that could allow an attacker to execute unauthorized code. By placing a malicious file in a specific location on the system, an attacker could trick the software into running it with elevated privileges. This could lead to a full compromise of the automation system, potentially impacting production data and operational integrity.
Technical details
An Untrusted Search Path vulnerability (CWE-426) exists in B&R Industrial Automation GmbH APROL versions prior to R 4.4-01P5. The application fails to properly validate or sanitize the search path used to locate and load external resources or libraries. A local attacker with file system access can exploit this by placing a malicious binary or library in a directory that is searched before the legitimate one. Successful exploitation allows for arbitrary code execution with the privileges of the APROL process. The issue is resolved in version R 4.4-01P5.
Affected products
- B&R Industrial Automation GmbH APROL before R 4.4-01P5
Timeline
- 2026-07-06: advisory: Initial publication of the advisory and CVE record.