CVE-2025-3450: B&r Industrial Automation Automation Runtime

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.

Affected products

Published 2025-10-07. Last modified 2026-06-17.