Executive brief
B&R Automation Runtime is a middleware system used to run industrial applications on controller hardware. A vulnerability in its System Diagnostics Manager (SDM) component could allow a remote attacker to crash the controller or delete data. This would result in a complete loss of availability for the industrial process being managed by the device.
Technical details
An improper resource locking vulnerability (CWE-413) exists in the System Diagnostics Manager (SDM) component of B&R Automation Runtime. The SDM is a web-based diagnostic interface served by the Automation Runtime webserver. An unauthenticated network-based attacker can exploit this by sending specially crafted messages to the affected system node. Successful exploitation allows the attacker to delete data or cause a denial of service (DoS) condition, effectively stopping the controller. The vulnerability is addressed in Automation Runtime versions 6.3 and Q4.93. Mitigation includes disabling SDM, which is the default state in version 6.0 and later.
Affected products
- B&R (ABB) Automation Runtime < 6.3, < Q4.93
Timeline
- 2026-05-26: advisory: CISA Advisory ICSA-26-146-04 published
- 2026-05-26: patched: Vendor fix available in versions 6.3 and Q4.93