CVE-2025-3450: exploitation status and patch state
CVE-2025-3450 · CVSS 10.0 CRITICAL · EPSS <1%
An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.
Is CVE-2025-3450 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.