CVE-2019-19102

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
29/04/2020
Last modified:
08/05/2020

Description

A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories. The vulnerability is also known as zip slip.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:* 4.0 (including) 4.0.32.15 (including)
cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:* 4.1 (including) 4.1.17.113 (including)
cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:* 4.2 (including) 4.2.14.119 (including)