Junglewise Threat Intelligence

CVE-2025-11043: ABB B&R Automation Studio

CVE-2025-11043 · Severity: high · CVSS 7.4 · Published 2026-05-05

Vendors: B&R Industrial Automation, ABB.

Executive brief

ABB B&R Automation Studio is a development environment used to create and manage industrial automation systems. A security flaw in how the software verifies digital certificates could allow an attacker to impersonate a trusted server. If exploited, this could lead to the theft of sensitive configuration data or the unauthorized modification of automation instructions, potentially disrupting manufacturing operations.

Technical details

An Improper Certificate Validation vulnerability (CWE-295) exists in the OPC-UA and ANSL over TLS client implementations within ABB B&R Automation Studio. The root cause is insufficient validation mechanisms for server certificates during the establishment of secure connections. An unauthenticated attacker with network access can exploit this by redirecting traffic (via DNS poisoning or routing manipulation) and presenting a specially crafted certificate. Successful exploitation enables Man-in-the-Middle (MitM) attacks, allowing the interception or alteration of data exchanged between the development environment and industrial controllers. The vulnerability is resolved in B&R Automation Studio version 6.5.

Affected products

  • ABB B&R Automation Studio < 6.5

Timeline

  • 2025-11-04: other: CVE ID assigned year prefix
  • 2026-05-05: advisory: CISA and ABB published the advisory

References

Related threats