PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-45481 B&R Industrial Automation CVE debrief

CVE-2024-45481 is a high-severity issue in B&R APROL versions before 4.4-00P5. CISA’s advisory says scripts using the SSH server do not fully filter special elements, which may allow an authenticated local attacker to authenticate as another legitimate user. B&R recommends patching or upgrading to a non-vulnerable version and changing secrets/passwords after applying the update.

Vendor
B&R Industrial Automation
Product
B&R APROL
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-24
Original CVE updated
2025-03-24
Advisory published
2025-03-24
Advisory updated
2025-03-24

Who should care

OT/ICS operators, plant administrators, and security teams responsible for B&R APROL systems, especially any environment that allows authenticated local access to hosts running SSH-related scripts.

Technical summary

The advisory describes an incomplete filtering problem in scripts that use the SSH server on B&R APROL <4.4-00P5. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates a local attack requiring low privileges and no user interaction, with potentially high impact to confidentiality, integrity, and availability. The stated outcome is authentication as another legitimate user, which makes access control and account boundaries the main concern.

Defensive priority

High. Prioritize remediation on any exposed B&R APROL installation before 4.4-00P5, because the issue affects authentication paths and is reachable by an authenticated local actor.

Recommended defensive actions

  • Apply the vendor patch or upgrade to a non-vulnerable B&R APROL version at the earliest opportunity.
  • Use the user manual to confirm the installed APROL version so affected systems are identified accurately.
  • Change all secrets and passwords after applying the update, as recommended by B&R.
  • Follow vendor and CISA ICS recommended practices for defense in depth, including limiting local access where possible and reviewing SSH-related administrative pathways.

Evidence notes

This debrief is based on the supplied CISA CSAF advisory ICSA-25-093-05, published 2025-03-24 and initially revised 1.0.0 the same day. The advisory names B&R APROL <4.4-00P5 as affected and states that incomplete filtering of special elements in scripts using the SSH server may allow an authenticated local attacker to authenticate as another legitimate user. The supplied CVSS score is 7.8 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Remediation guidance in the corpus is to patch or upgrade and then change secrets/passwords.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-45481 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-45481

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-45481 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45481

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-093-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-093-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.