CVE-2026-79679

8.7

B&R Industrial Automation GmbH · mapp Services

A use of weak credentials vulnerability in B&R Industrial Automation GmbH mapp Audit within mapp Services allows potential system compromise.

Executive summary

B&R Industrial Automation GmbH mapp Services is vulnerable to a credential weakness that could allow an attacker to achieve high-impact system manipulation.

Vulnerability

This vulnerability involves the use of weak credentials (CWE-1391) within the mapp Audit component. The flaw is reachable by an unauthenticated attacker over the network, though it requires specific conditions to be met (AT:P).

Business impact

The presence of weak credentials in an industrial automation environment poses a significant risk to operational integrity. With a CVSS score of 8.7, this vulnerability presents a high risk for unauthorized system configuration changes or process disruption, which could lead to severe downtime or safety concerns in industrial settings.

Remediation

Immediate Action: Upgrade mapp Services to version 6.8.0 or later as mandated by the vendor security advisory.

Proactive Monitoring: Review system access logs for anomalous authentication attempts or unauthorized configuration changes within the mapp Audit environment.

Compensating Controls: Implement strict network segmentation to ensure the affected industrial services are not exposed to the public internet, and utilize internal firewalls to limit access to authorized personnel only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity of this vulnerability, organizations must treat the update to version 6.8.0 as a priority. Administrators should coordinate with industrial control system teams to schedule the necessary updates during the next available maintenance window to minimize operational impact while addressing the risk of unauthorized access.

More B&R Industrial Automation GmbH CVEs

Sources