CVE-2025-3450
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-07

Last updated on: 2025-10-08

Assigner: Asea Brown Boveri Ltd. (ABB)

Description
An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-07
Last Modified
2025-10-08
Generated
2026-05-09
AI Q&A
2025-10-07
EPSS Evaluated
2026-05-08
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
br_automation automation_runtime *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-413 The product does not lock or does not correctly lock a resource when the product must have exclusive access to the resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an Improper Resource Locking issue in B&R Industrial Automation Automation Runtime versions from 6.0 before 6.3, before Q4.93. It means that the software does not correctly manage access to resources, potentially allowing unauthorized or conflicting operations.


How can this vulnerability impact me? :

The vulnerability has a high severity score (CVSS v3.1 score of 10.0), indicating it can be exploited remotely without privileges or user interaction, leading to high impact on integrity and availability. This could result in unauthorized actions or disruption of the affected system's operations.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart