CVE-2025-3449
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-07

Last updated on: 2025-10-08

Assigner: Asea Brown Boveri Ltd. (ABB)

Description
A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-07
Last Modified
2025-10-08
Generated
2026-05-07
AI Q&A
2025-10-07
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
br_automation runtime *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-340 The product uses a scheme that generates numbers or identifiers that are more predictable than required.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves the generation of predictable numbers or identifiers in B&R Industrial Automation Automation Runtime versions from 6.0 before 6.4. Predictable numbers or identifiers can be exploited by attackers to guess or predict values that should be random or unique, potentially leading to security issues.


How can this vulnerability impact me? :

The impact of this vulnerability is limited but could allow an attacker to predict identifiers or numbers generated by the affected Automation Runtime, which might lead to unauthorized actions or information disclosure. The CVSS scores indicate a low to medium severity with limited confidentiality and integrity impact and no availability impact.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart