Executive brief
ABB B&R Automation Runtime, a middleware system used to manage industrial control applications, contains multiple vulnerabilities in its System Diagnostics Manager (SDM) component. If exploited, these flaws could allow an attacker to take over active user sessions, execute malicious code in a user's web browser, or inject harmful data into exported diagnostic files. This could lead to unauthorized access to industrial controller information or the compromise of workstations used by plant operators.
Technical details
Three distinct vulnerabilities exist in the System Diagnostics Manager (SDM) component of ABB B&R Automation Runtime versions prior to 6.4. CVE-2025-3449 involves the generation of predictable session identifiers, allowing unauthenticated network attackers to hijack established sessions. CVE-2025-3448 is a reflected cross-site scripting (XSS) vulnerability that enables the execution of arbitrary JavaScript in a user's browser context via malicious links. CVE-2025-11498 is a CSV injection (formula injection) flaw where an attacker can inject malicious formulas into generated CSV files, which may execute when the file is opened in spreadsheet software. All vulnerabilities require some level of user interaction, such as clicking a link or opening a file. These issues are resolved in Automation Runtime version 6.4.
Affected products
- ABB B&R Automation Runtime < 6.4
CVE identifiers
- CVE-2025-3448
- CVE-2025-3449
- CVE-2025-11498
Timeline
- 2026-05-21: advisory: CISA published advisory ICSA-26-141-04
- 2026-05-21: patched: Vulnerabilities fixed in Automation Runtime 6.4