CVE-2026-6900 Details
Description
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
A vulnerability exists in B&R Industrial Automation APROL versions prior to R 4.4-01P5, due to improper validation of certificates in the LDAP Server Connector. This vulnerability may enable network-based attackers to perform adversary-in-the-middle attacks, leading to information disclosure or identity spoofing.
Users are advised to update to APROL version 4.4-01P5 or later. Instructions for installing updates are available in the user manual. To address the vulnerability, enable TLS certificate verification system-wide by adding 'TLS_REQCERT demand' to the LDAP configuration file. Additionally, configure certificate verification for each user account by creating a '.ldaprc' file in the home directory of each account and adding the appropriate certificate directory path. After preparing the certificate directories, deploy trusted certificates by manually copying the server's trusted issuer certificate to the designated directories.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 6, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P011-661853b7.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| B&R Industrial Automation APROL | < R 4.4-01P5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | New CVE Received | [email protected] |
Volerion