Junglewise Threat Intelligence

CVE-2025-11044: ABB B&R Automation Runtime

CVE-2025-11044 · Severity: high · CVSS 6.8 · Published 2026-05-05

Technologies: B&R Industrial Automation Automation Runtime. Vendors: B&R Industrial Automation, ABB.

Executive brief

ABB B&R Automation Runtime is a real-time operating system used to control industrial machinery and manufacturing processes. A vulnerability in its communication server could allow a remote attacker to crash the system, leading to a permanent stop of industrial operations. This could result in production downtime and require manual intervention to restore services.

Technical details

An 'Allocation of Resources Without Limits or Throttling' vulnerability (CWE-770) exists in the ANSL-Server component of ABB B&R Automation Runtime. An unauthenticated remote attacker can exploit a race condition by sending specially crafted messages to the device. Successful exploitation results in a permanent denial-of-service (DoS) condition, causing the product to stop. The vulnerability is more likely to be exploited in environments with shorter cycle times. Patches are available in Automation Runtime versions 6.5 and R4.93.

Affected products

  • ABB B&R Automation Runtime < 6.5, < R4.93

Timeline

  • 2026-05-05: advisory: CISA Advisory ICSA-26-125-03 published
  • 2026-05-05: patched: Fixes released in versions 6.5 and R4.93

References

Related threats