Security Issues addressed in APROL R 4.4-01P5

Act NowCVSS 9.8sa26p011Jul 6, 2026
Manufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

APROL versions before R 4.4-01P5 contain multiple security vulnerabilities affecting certificate verification, component integrity, and system resource handling. An attacker could exploit these issues to spoof identities, elevate privileges, or impact system availability. The vulnerabilities relate to improper TLS certificate validation (CWE-295), insecure component loading (CWE-426), race conditions (CWE-367), improper resource management (CWE-400), and weak cryptography (CWE-326).

What this means
What could happen
An attacker on the network could bypass authentication controls, execute unauthorized code with elevated privileges, or cause the APROL control system to become unavailable. This could allow manipulation of batch processes, recipe data, or process setpoints.
Who's at risk
Manufacturing facilities using ABB APROL batch management and process control systems for recipe execution, data logging, and process automation. This affects any site relying on APROL for pharmaceutical, chemical, food, or discrete manufacturing batch operations where authentication integrity and system availability are critical.
How it could be exploited
An attacker with network access could intercept or spoof LDAP authentication traffic by presenting an invalid certificate (if certificate verification is not enforced). They could also exploit race conditions or weak cryptographic validation in component loading to inject malicious code that runs with system privileges. The CVSS vector indicates remote network access with no authentication required.
Prerequisites
  • Network access to the APROL system
  • No valid credentials required for initial exploitation
  • Access to LDAP authentication traffic (for man-in-the-middle attacks) or ability to influence system startup (for component loading attacks)
remotely exploitableno authentication requiredlow complexityhigh EPSS score (43.7%)affects batch control and authorization systems
Exploitability
Likely to be exploited — EPSS score 44.3%
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (1)
ProductAffected VersionsFix Status
APROL <R 4.4-01P5<R 4.4-01P5R 4.4-01P5
Remediation & Mitigation
0/6
Do now
0/5
HARDENINGAdd TLS_REQCERT demand directive to /etc/openldap/ldap.conf to enforce certificate verification
HARDENINGCreate .ldaprc configuration files in each user account home directory (engineering, runtime, operator) with appropriate TLS_CACERTDIR paths to issuer certificate directories
HARDENINGRun 'openssl rehash' on all issuer certificate directories to index certificates for verification
HARDENINGManually deploy trusted LDAP server issuer certificates to the configured certificate directories
HARDENINGRemove or replace all wildcard AliasMatch directives in Apache configuration to prevent unintended route aliasing
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate APROL to version R 4.4-01P5 or later
API: /api/v1/advisories/87d97c6e-3e74-4cb6-9fca-923470c352b7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Security Issues addressed in APROL R 4.4-01P5 | CVSS 9.8 - OTPulse