CVE-2025-3450
CVSS 10 CRITICAL: an Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and… EPSS 0.3% (20º percentile).
Vulnerabilità · 128 giorni fa
Un singolo bug di resource-locking di SDM può arrestare lo stesso ABB B&R Automation Runtime, quindi il rischio è il downtime del controller, non solo il crash di un componente locale. Sui sistemi in cui SDM è abilitato, un attaccante di rete non autenticato può mandare in crash il runtime e interrompere la disponibilità del controllo.
CVSS 10 CRITICAL: an Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and… EPSS 0.3% (20º percentile).
1 fonte che coprono questa storia
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) | CISA
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory.
Part of the PlainSec briefing for 2026-05-26