A single SDM resource-locking bug can stop ABB B&R Automation Runtime itself, so the risk is controller downtime, not just a local component crash. On systems where SDM is enabled, an unauthenticated network attacker can knock over the runtime and interrupt control availability.
CISA says CVE-2025-3450 affects Automation Runtime before 6.3 and before Q4.93. ABB B&R says the issue is fixed in Automation Runtime 6.3 and Q4.93, and the advisory ties the flaw to the SDM component used across critical sectors.
The practical risk is process interruption on exposed or production systems that rely on ABB controllers. This is a service-availability problem that can persist as an operational outage even after the software is patched.