CVE-2025-3449
BaseFortify
Publication date: 2025-10-07
Last updated on: 2025-10-08
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| br_automation | runtime | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-340 | The product uses a scheme that generates numbers or identifiers that are more predictable than required. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the generation of predictable numbers or identifiers in B&R Industrial Automation Automation Runtime versions from 6.0 before 6.4. Predictable numbers or identifiers can be exploited by attackers to guess or predict values that should be random or unique, potentially leading to security issues.
How can this vulnerability impact me? :
The impact of this vulnerability is limited but could allow an attacker to predict identifiers or numbers generated by the affected Automation Runtime, which might lead to unauthorized actions or information disclosure. The CVSS scores indicate a low to medium severity with limited confidentiality and integrity impact and no availability impact.