Vulnerabilities · 116 days ago
The problem is not one faulty box. The same nine flaws span multiple ABB B&R PC families, so separate patch tracks by model will miss part of the exposed fleet.
CISA maps CVE-2023-45229 through CVE-2023-45237 across APC4100, APC910, C80, MPC3100, PPC1200, PPC900, and APC2200. The exposed versions differ by model, and the vendor update closes risks that include remote code execution, DoS, DNS cache poisoning, and sensitive data extraction.
That makes this an operations issue as much as a security one. Industrial PC estates often age on different schedules, so the shared vulnerability set creates a coordinated remediation problem across production environments.
CVEs in this update
9 CVEs
0 critical · 5 high · 4 medium · 0 low
0 in CISA KEV · 5 with EPSS above 1%
Highest severity: CVE-2023-45230 · 8.3 HIGH
Highest EPSS: CVE-2023-45232 · 2.1%
1 source covering this story
ABB B&R Automation Runtime | CISA
ABB B&R Automation Runtime Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory.
ABB B&R PCs Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory.
ABB B&R Automation Studio | CISA
ABB B&R Automation Studio Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory.
Part of the PlainSec briefing for 2026-05-22