CRITICAL🇵🇱 Wersja polska

CVE-2025-3450

CVSS 9.3v4.0pub. 2025-10-07upd. 2026-04-15

An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.

🤖 AI Analysis
How it works

The flaw consists of improper resource locking (CWE-413) in the SDM component of B&R Automation Runtime. An attacker can send specially crafted requests over the network without any authentication, leading to data deletion. The lack of a proper resource locking mechanism causes data operations to not be adequately protected against concurrent or unauthorized network access.

Impact

An attacker can delete system data, resulting in service interruption and causing a denial of service (DoS) state. The vulnerability also affects data integrity in master and subordinate systems associated with the automation environment.

Mitigation & patch

B&R Automation Runtime should be updated to version 6.3 or later, or to version Q4.93 or later. Detailed information about available patches is available in the vendor's security advisory: https://www.br-automation.com/fileadmin/SA25P002-f6a69e61.pdf

Who is affected

B&R Automation Runtime in versions earlier than 6.3 and earlier than Q4.93

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References