CVE-2025-3450
BaseFortify
Publication date: 2025-10-07
Last updated on: 2025-10-08
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| br_automation | automation_runtime | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-413 | The product does not lock or does not correctly lock a resource when the product must have exclusive access to the resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Resource Locking issue in B&R Industrial Automation Automation Runtime versions from 6.0 before 6.3, before Q4.93. It means that the software does not correctly manage access to resources, potentially allowing unauthorized or conflicting operations.
How can this vulnerability impact me? :
The vulnerability has a high severity score (CVSS v3.1 score of 10.0), indicating it can be exploited remotely without privileges or user interaction, leading to high impact on integrity and availability. This could result in unauthorized actions or disruption of the affected system's operations.