CVE-2024-5800

Severity CVSS v4.0:
HIGH
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
12/08/2024
Last modified:
19/12/2025

Description

Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:br-automation:automation_runtime:*:*:*:*:*:*:*:* 6.0.2 (excluding)


References to Advisories, Solutions, and Tools