An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.