Threat reportVulnerabilityTL-2026-0593
ABB B&R Automation Runtime SDM CVE-2025-3450 — Unauthenticated Network DoS via Improper Resource Locking
ABB B&R Automation Runtime SDM CVE-2025-3450 (TL-2026-0593), also tracked as ICSA-26-146-04, is a critical-severity software vulnerability scored CVSS 10, first published 2026-05-26. It has no confirmed attribution, affects ABB (B&R Industrial Automation) Automation Runtime, references 1 CVE (CVE-2025-3450), maps to 16 MITRE ATT&CK techniques (T1046, T1082, T1133), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-0593
- Threat ID
- TL-2026-0593
- Also known as
- ICSA-26-146-04, ABB PSIRT SA25P002
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- chemical, communications, critical-manufacturing, dams, energy, healthcare, information-technology, water-wastewater
- Target regions
- Worldwide, North America, Europe, Asia-Pacific, South America, Middle East, Africa
- Detection rules
- 9
- Indicators of compromise
- 12
How ABB B&R Automation Runtime SDM CVE-2025-3450 works
B&R Automation Runtime versions before 6.3 and before Q4.93 contain an Improper Resource Locking flaw (CWE-413) in the System Diagnostics Manager (SDM) webpage component, served by the Automation Runtime webserver. An unauthenticated network-based attacker who can reach the SDM endpoint can deliver a specially crafted message that causes the affected controller to delete data and halt, producing a denial-of-service condition on the running PLC node. ABB PSIRT rates the issue CVSS 3.1 10.0 CRITICAL (S:C/C:N/I:H/A:H) and CVSS 4.0 9.3, and it has been republished by CISA as ICSA-26-146-04 across Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare, IT, and Water/Wastewater sectors worldwide.
B&R Automation Runtime (AR) is the middleware/operating environment that executes customer applications on B&R (an ABB business) PLCs and industrial controllers. AR exposes an embedded webserver providing administrative and diagnostic interfaces, one of which is the System Diagnostics Manager (SDM) — a browser-accessible page presenting real-time diagnostic information about the running controller (task lists, module states, network statistics, log buffers). CVE-2025-3450 is an Improper Resource Locking (CWE-413) defect in the SDM component: under specific request sequencing, internal data structures protected by inadequate or absent mutual-exclusion primitives can be concurrently modified or freed, leading to data deletion and termination of the affected system node.
The ABB PSIRT advisory SA25P002 — republished verbatim by CISA as ICSA-26-146-04 on 2026-05-26 — states that an attacker exploits the flaw by crafting and sending a message to an affected system node. The attacker requires only network reachability to the AR webserver; no authentication, no user interaction, and no privilege on the controller is needed. The CVSS 3.1 Scope is Changed (S:C) because the SDM is a component of Automation Runtime, but successful exploitation impacts the entire controller's integrity and availability, halting the PLC and any downstream physical process it controls. Confidentiality impact is None — the bug deletes data and stops execution; it does not exfiltrate process variables or recipes. Both ABB's CVSS 3.1 (10.0) and CVSS 4.0 (9.3) scores agree this is a CRITICAL ICS-impacting flaw.
B&R discovered the vulnerability through its own internal security analysis; no public PoC exists at the time of original disclosure (2025-10-07) and no in-the-wild exploitation has been reported. Even so, the bug is highly attractive to opportunistic and state-aligned actors targeting OT environments: the AR webserver is commonly bound to engineering or supervisory VLANs that, in poorly-segmented ICS environments, reach the corporate network or even the public internet through misconfigured firewalls. Asset owners exposing the SDM endpoint to unauthenticated network traffic should treat this as a controller-stopping condition reachable by a single packet sequence — equivalent operationally to an unauthenticated 'remote shutdown' primitive against any reachable B&R PLC running affected AR versions.
Fixed versions are Automation Runtime 6.3 and Automation Runtime Q4.93. Critically, beginning with Automation Runtime 6.0 the SDM component is disabled by default, materially reducing the attack surface on greenfield 6.x deployments; AR versions prior to 6.0 ship with SDM available and require explicit deactivation in the Automation Studio project. ABB also recommends configuring the AR webserver to require HTTPS, enabling mutual TLS ('Validate SSL communication partner') in Automation Studio, and restricting the webserver TCP listener to trusted IP ranges using the Automation Runtime host-based firewall. None of these compensating controls is a substitute for patching: a properly-segmented but enabled SDM endpoint is still vulnerable to anyone with engineering-network access (insider threat, lateral movement from a compromised HMI/engineering workstation, or VPN intrusion).
Exploit chain (theoretical, from advisory text): 1) Reconnaissance — attacker scans the OT network for AR webserver instances, identified by characteristic HTTP/HTTPS banners on default or operator-configured ports and the presence of the SDM URL path. 2) Initial Access — attacker connects to the AR webserver from any reachable host (engineering workstation foothold, compromised HMI, mis-segmented IT/OT bridge, or directly exposed control system). 3) Execution — attacker issues a specially crafted HTTP(S) request sequence to the SDM endpoint that triggers the improper-locking condition in AR's diagnostic data structures. 4) Impact — the locking flaw causes SDM-managed data to be deleted and the controller process to halt. The affected B&R system node stops, which in ICS contexts typically translates into a stopped scan cycle, loss of view/loss of control for HMI/SCADA operators, and potentially a safe-state trip of downstream physical equipment depending on watchdog and safety-instrumented system configuration.
Detection-relevant artefacts on networks running AR include: unusual HTTP/HTTPS requests to SDM URLs from non-engineering hosts; sudden controller cyclic-task termination events surfaced via OPC UA / mapp Services telemetry; AR webserver process restarts; loss-of-comms alarms in SCADA against B&R PLC IPs. Mitigations recommended by ABB: upgrade to AR 6.3 / Q4.93; disable SDM where not required; enforce HTTPS + mTLS for the AR webserver; restrict the webserver to trusted IPs via the AR host-based firewall; segment OT from IT; restrict engineering-network access to authorised maintenance personnel and time windows.
MITRE ATT&CK techniques used in TL-2026-0593
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Impact
T1485 Data Destruction; T1489 Service Stop; T1499 Endpoint Denial of Service; T1499.003 Endpoint Denial of Service: Application Exhaustion Flood; T1499.004 Endpoint Denial of Service: Application or System Exploitation; T1529 System Shutdown/Reboot
Resource Development
T1587.004 Develop Capabilities: Exploits
Reconnaissance
T1590 Gather Victim Network Information; T1592.002 Gather Victim Host Information: Software; T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning
Affected products and versions in ABB B&R Automation Runtime SDM CVE-2025-3450
- ABB (B&R Industrial Automation) — Automation Runtime
Vulnerable versions: <6.3; <Q4.93
Fixed in: 6.3; Q4.93 - ABB (B&R Industrial Automation) — Automation Runtime SDM component (System Diagnostics Manager)
Vulnerable versions: Bundled with Automation Runtime <6.3 and <Q4.93
Fixed in: Bundled with Automation Runtime 6.3 and Q4.93; disabled by default on AR >=6.0
Remediation for ABB B&R Automation Runtime SDM CVE-2025-3450
Patches
- Automation Runtime 6.3 (vendor fix)
- Automation Runtime Q4.93 (vendor fix backport for Q-series LTS branch)
Immediate actions
- Inventory all B&R / ABB Automation Runtime deployments and identify version (Automation Studio: Project Properties > Configuration > Runtime version; or via AR webserver banner)
- Verify whether the SDM endpoint is enabled on each controller (default-disabled on AR >=6.0, default-available on AR <6.0)
- Where SDM is not required for active maintenance, disable it in the Automation Studio project per Automation Help GUID 1d915d67-07f7-4034-a472-c204b5cabbfe
- Block external and corporate-network access to the AR webserver TCP listener at perimeter and IT/OT segmentation firewalls
- Restrict AR webserver access to trusted engineering-workstation IP ranges using the Automation Runtime host-based firewall (Automation Help GUID 75b8994b-f97a-4e0f-8278-43c7a737e65f)
Workarounds
- Disable the System Diagnostics Manager (SDM) component in the Automation Studio project where not required
- Restrict AR webserver listener to engineering-network IPs via Automation Runtime host-based firewall
- Require HTTPS + mTLS on the AR webserver (also impacts mapp View clients)
- Time-box SDM enablement to the minimum window required for active maintenance tasks
Longer-term hardening
- Upgrade affected controllers to Automation Runtime 6.3 or Q4.93 during planned outage windows
- Enforce HTTPS for the AR webserver and configure mutual TLS (Validate SSL communication partner) in Automation Studio (Automation Help GUID 01ced6c0-28ef-4aaa-bd05-2442b971859c) — note this also affects mapp View and other AR webserver consumers
- Implement Purdue-model network segmentation isolating B&R PLCs at Level 1/2 from corporate IT at Level 4/5 via stateful firewalls with explicit allowlists
- Deploy passive OT monitoring (Claroty, Nozomi, Dragos, Tenable.ot) to detect anomalous HTTP/HTTPS traffic to AR webservers and AR controller restarts
- Establish authenticated VPN + jump-host pattern for any remote engineering access to OT, rather than direct AR webserver exposure
CVEs associated with ABB B&R Automation Runtime SDM CVE-2025-3450
Weaknesses (CWE) in ABB B&R Automation Runtime SDM CVE-2025-3450
Timeline of ABB B&R Automation Runtime SDM CVE-2025-3450
- ABB B&R internal security analysis identifies the Improper Resource Locking flaw in the Automation Runtime SDM component (exact discovery date not disclosed; placeholder reflects approximate window prior to coordinated disclosure).
- NVD publishes CVE-2025-3450 with CVSS 3.1 base score 10.0 CRITICAL (S:C/C:N/I:H/A:H) and CVSS 4.0 base score 9.3 CRITICAL, both supplied by ABB PSIRT (cybersecurity@ch.abb.com).
- ABB PSIRT publishes Security Advisory SA25P002 disclosing CVE-2025-3450 and releases fixed Automation Runtime versions 6.3 and Q4.93.
- NVD record for CVE-2025-3450 receives a metadata update (last-modified timestamp).
- Threadlinqs Intelligence Platform publishes TL-2026-0593 covering CVE-2025-3450 with detection content, simulation guidance, and remediation playbook for SOC and OT defenders.
- CISA republishes ABB PSIRT SA25P002 as ICS Advisory ICSA-26-146-04, highlighting impact across eight critical-infrastructure sectors worldwide.
- As of 2026-05-29, CVE-2025-3450 is patched (ABB B&R Automation Runtime 6.3/Q4.93, SDM disabled by default on AR 6.0+) with no public PoC, no in-the-wild exploitation, and no CISA KEV listing. It remains a live concern: a CVSS-10 unauthenticated OT controller-halt flaw, freshly CISA-republished (ICSA-26-146-04, 2026-05-26) against slow-to-patch critical-infrastructure fleets.
Sources cited for ABB B&R Automation Runtime SDM CVE-2025-3450
- CISA ICS Advisory ICSA-26-146-04 — ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
- ABB PSIRT Security Advisory SA25P002 (vendor PDF)
- NVD — CVE-2025-3450
- MITRE CWE-413: Improper Resource Locking
- B&R Automation Runtime product page
- CISA — Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies
- CISA ICS-TIP-12-146-01B — Targeted Cyber Intrusion Detection and Mitigation Strategies
Detection coverage for TL-2026-0593
As of 2026-05-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0593 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.