CVE-2025-3450: B&r Industrial Automation Automation Runtime
Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.
An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.
Affected products
- B&r Industrial Automation Automation Runtime: from 6.0, before 6.3 (fixed in 6.3); from 4.0, before Q4.93 (fixed in Q4.93)
Published 2025-10-07. Last modified 2026-06-17.