CVE-2025-3450
CVSS 10 CRITICAL: an Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and… EPSS 0.3% (20º percentile).
Vulnerabilità ed exploit · DDoS
Un singolo bug di resource-locking di SDM può arrestare lo stesso ABB B&R Automation Runtime, quindi il rischio è il downtime del controller, non solo il crash di un componente locale. Sui sistemi in cui SDM è abilitato, un attaccante di rete non autenticato può mandare in crash il runtime e interrompere la disponibilità del controllo.
1 fonte · 26 mag
CVSS 10 CRITICAL: an Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and… EPSS 0.3% (20º percentile).
CISA Advisories
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) | CISA
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory.
originalePart of the PlainSec briefing for 2026-05-26
Every edition of this story: ABB Controller Runtime Può Essere Arrestato Remotamente