CVE-2025-3450
CVSS 10 CRITICAL: an Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and… EPSS 0.3% (20th percentile).
Vulnerabilities · 111 days ago
A single SDM resource-locking bug can stop ABB B&R Automation Runtime itself, so the risk is controller downtime, not just a local component crash. On systems where SDM is enabled, an unauthenticated network attacker can knock over the runtime and interrupt control availability.
CISA says CVE-2025-3450 affects Automation Runtime before 6.3 and before Q4.93. ABB B&R says the issue is fixed in Automation Runtime 6.3 and Q4.93, and the advisory ties the flaw to the SDM component used across critical sectors.
The practical risk is process interruption on exposed or production systems that rely on ABB controllers. This is a service-availability problem that can persist as an operational outage even after the software is patched.
CVSS 10 CRITICAL: an Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and… EPSS 0.3% (20th percentile).
1 source covering this story
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) | CISA
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory.
Part of the PlainSec briefing for 2026-05-26