PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-10210 B&R Industrial Automation GmbH CVE debrief

CVE-2024-10210 is a high-severity vulnerability in the APROL Web Portal used by B&R APROL versions before 4.4-00P5. According to the CISA advisory, an authenticated network-based attacker may be able to access data from the file system. B&R recommends applying the patch or upgrading to a non-vulnerable version and changing secrets/passwords after remediation.

Vendor
B&R Industrial Automation GmbH
Product
B&R APROL
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-24
Original CVE updated
2025-03-24
Advisory published
2025-03-24
Advisory updated
2025-03-24

Who should care

Organizations running B&R APROL, especially teams responsible for the APROL Web Portal, OT operations, and industrial control system security. Prioritize this if authenticated users have access to the portal or if the environment relies on sensitive local file data.

Technical summary

The advisory describes an External Control of File Name or Path issue in the APROL Web Portal. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N, which indicates remote network reachability, required authentication, no user interaction, high confidentiality impact, and low integrity impact. The affected product is listed as B&R APROL < 4.4-00P5 in the CSAF record.

Defensive priority

High. This is a remote, authenticated issue with high confidentiality impact, and the vendor advises patching or upgrading at the earliest convenience.

Recommended defensive actions

  • Apply the vendor patch or upgrade to a non-vulnerable B&R APROL version as soon as practical.
  • Use the vendor manual to confirm the installed APROL version before and after remediation.
  • After updating, change passwords and other secrets referenced by the vendor advisory.
  • Review who can authenticate to the APROL Web Portal and restrict access to only required operators and systems.
  • Follow the linked CISA and B&R industrial-control-system defense-in-depth guidance for layered protections.

Evidence notes

Primary evidence comes from the CISA CSAF advisory ICSA-25-093-05 for CVE-2024-10210, which identifies the flaw as an External Control of File Name or Path issue in the APROL Web Portal and lists the affected product as B&R APROL < 4.4-00P5. The advisory also includes vendor remediation guidance to patch or upgrade and to change passwords/secrets afterward. Official reference links from CISA and B&R were used as the evidence corpus; no unsupported exploitation claims are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-10210 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-10210

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-10210 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10210

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-093-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-093-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.