{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory.\n\nAn attacker who successfully exploited this vulnerability could cause the product to stop.",
        "title": "Summary"
      },
      {
        "category": "other",
        "text": "For any installation of software-related B&R products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n-Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general-purpose network (e.g. office or home networks).\n-Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n-Never connect programming software or computers containing programing software to any network other than the network for the devices that it is intended for.\n-Scan all data imported into your environment before use to detect potential malware infections.\n-Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n-Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n-When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recog-nize that VPNs may have vulnerabilities and should be updated to the most current version availa-ble. Also, understand that VPNs are only as secure as the connected devices.\n\nMore information on recommended practices can be found in the following documents:\nDefense in Depth for B&R products\n",
        "title": "General security recommendations"
      },
      {
        "category": "other",
        "text": "For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n",
        "title": "Support"
      },
      {
        "category": "legal_disclaimer",
        "text": "The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\n\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.\n",
        "title": "Notice"
      },
      {
        "category": "general",
        "text": "Deactivate the vulnerable component\n\nThe SDM is deactivated by default on Automation Runtime version >=6.0. For Automation Runtime versions <6.0, the SDM can be deactivated in the Automation Studio project. Please refer to Automation Help GUID 1d915d67-07f7-4034-a472-c204b5cabbfe for further guidance.\n\nAccess to the System Diagnostic Manager (SDM) shall be restricted to trusted personnel through appropriate external security measures. If SDM is required solely for maintenance purposes, it should be enabled or access granted only for the minimum time necessary to perform the task.\n\nLimit accessibility\n\nB&R recommends in general to configure the HTTP protocol over TLS (HTTPS). \n\nCustomers may restrict access to the webserver by configuring mutual TLS (mTLS) in the Automation Studio project (Option “Validate SSL communication partner”). Be aware that configuring mTLS would impact also other applications using the AR webserver (e.g. mapp View). Please refer to Automation Help GUID 01ced6c0-28ef-4aaa-bd05-2442b971859c to learn more about the TLS Configuration in Automation Studio.\n\nIn addition, accessibility of the webserver can be limited to trusted IP addresses using the Automation Runtime host-based firewall. Please refer to Automation Help GUID 75b8994b-f97a-4e0f-8278-43c7a737e65f for details.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n\n",
        "title": "Mitigating factors"
      }
    ],
    "publisher": {
      "category": "vendor",
      "name": "ABB PSIRT",
      "namespace": "https://global.abb/group/en/technology/cyber-security/alerts-and-notifications"
    },
    "references": [
      {
        "category": "self",
        "summary": "B&R Advisory Link",
        "url": "https://www.br-automation.com/fileadmin/SA25P002.pdf"
      },
      {
        "category": "self",
        "summary": "B&R CYBERSECURITY ADVISORY - CSAF Version",
        "url": "https://psirt.abb.com/csaf/2025/sa25p002.json"
      }
    ],
    "title": "B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)",
    "tracking": {
      "current_release_date": "2025-10-07T00:30:00.000Z",
      "generator": {
        "date": "2025-10-02T11:48:34.497Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.36"
        }
      },
      "id": "SA25P002",
      "initial_release_date": "2025-10-07T00:30:00.000Z",
      "revision_history": [
        {
          "date": "2025-10-07T00:30:00.000Z",
          "legacy_version": "A",
          "number": "1",
          "summary": "Initial version."
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<6.3",
                "product": {
                  "name": "Automation Runtime <6.3",
                  "product_id": "AV1"
                }
              },
              {
                "category": "product_version",
                "name": "6.3",
                "product": {
                  "name": "Automation Runtime 6.3",
                  "product_id": "FX1"
                }
              },
              {
                "category": "product_version_range",
                "name": "<Q4.93",
                "product": {
                  "name": "Automation Runtime <Q4.93",
                  "product_id": "AV2"
                }
              },
              {
                "category": "product_version",
                "name": "Q4.93",
                "product": {
                  "name": "Automation Runtime Q4.93",
                  "product_id": "FX2"
                }
              }
            ],
            "category": "product_name",
            "name": "Automation Runtime"
          }
        ],
        "category": "vendor",
        "name": "B&R"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-3450",
      "cwe": {
        "id": "CWE-413",
        "name": "Improper Resource Locking"
      },
      "notes": [
        {
          "category": "description",
          "text": "An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "FX1",
          "FX2"
        ],
        "known_affected": [
          "AV1",
          "AV2"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2025-3450",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3450"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "The problem is corrected in Automation Runtime versions 6.3 and Q4.93.\n\nThe System Diagnostic Manager (SDM) is disabled by default in Automation Runtime 6 and is not in-tended be enabled on active systems located outside properly secured production networks or in facilities lacking adequate physical and logical access controls to prevent any form of unauthorized interaction. For customers who use SDM on their systems, B&R recommends applying the update at the earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.\n",
          "product_ids": [
            "AV1",
            "AV2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 10,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.7,
            "environmentalSeverity": "HIGH",
            "exploitCodeMaturity": "UNPROVEN",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "scope": "CHANGED",
            "temporalScore": 8.7,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H/E:U/RL:O/RC:C",
            "version": "3.1"
          },
          "products": [
            "AV1",
            "AV2"
          ]
        }
      ],
      "title": "CVE-2025-3450"
    }
  ]
}