# ABB B&R Automation Runtime SDM CVE-2025-3450 — Unauthenticated Network DoS via Improper Resource Locking

> B&R Automation Runtime versions before 6.3 and before Q4.93 contain an Improper Resource Locking flaw (CWE-413) in the System Diagnostics Manager (SDM) webpage component, served by the Automation Runtime webserver. An unauthenticated network-based attacker who can reach the SDM endpoint can deliver a specially crafted message that causes the affected controller to delete data and halt, producing a denial-of-service condition on the running PLC node. ABB PSIRT rates the issue CVSS 3.1 10.0 CRITICAL (S:C/C:N/I:H/A:H) and CVSS 4.0 9.3, and it has been republished by CISA as ICSA-26-146-04 across Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare, IT, and Water/Wastewater sectors worldwide.

- **Published:** 2026-05-26T00:00:00Z
- **Last reviewed:** 2026-05-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0593
- **ID:** TL-2026-0593
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-3450

## Description

B&R Automation Runtime (AR) is the middleware/operating environment that executes customer applications on B&R (an ABB business) PLCs and industrial controllers. AR exposes an embedded webserver providing administrative and diagnostic interfaces, one of which is the System Diagnostics Manager (SDM) — a browser-accessible page presenting real-time diagnostic information about the running controller (task lists, module states, network statistics, log buffers). CVE-2025-3450 is an Improper Resource Locking (CWE-413) defect in the SDM component: under specific request sequencing, internal data structures protected by inadequate or absent mutual-exclusion primitives can be concurrently modified or freed, leading to data deletion and termination of the affected system node.

The ABB PSIRT advisory SA25P002 — republished verbatim by CISA as ICSA-26-146-04 on 2026-05-26 — states that an attacker exploits the flaw by crafting and sending a message to an affected system node. The attacker requires only network reachability to the AR webserver; no authentication, no user interaction, and no privilege on the controller is needed. The CVSS 3.1 Scope is Changed (S:C) because the SDM is a component of Automation Runtime, but successful exploitation impacts the entire controller's integrity and availability, halting the PLC and any downstream physical process it controls. Confidentiality impact is None — the bug deletes data and stops execution; it does not exfiltrate process variables or recipes. Both ABB's CVSS 3.1 (10.0) and CVSS 4.0 (9.3) scores agree this is a CRITICAL ICS-impacting flaw.

B&R discovered the vulnerability through its own internal security analysis; no public PoC exists at the time of original disclosure (2025-10-07) and no in-the-wild exploitation has been reported. Even so, the bug is highly attractive to opportunistic and state-aligned actors targeting OT environments: the AR webserver is commonly bound to engineering or supervisory VLANs that, in poorly-segmented ICS environments, reach the corporate network or even the public internet through misconfigured firewalls. Asset owners exposing the SDM endpoint to unauthenticated network traffic should treat this as a controller-stopping condition reachable by a single packet sequence — equivalent operationally to an unauthenticated 'remote shutdown' primitive against any reachable B&R PLC running affected AR versions.

Fixed versions are Automation Runtime 6.3 and Automation Runtime Q4.93. Critically, beginning with Automation Runtime 6.0 the SDM component is disabled by default, materially reducing the attack surface on greenfield 6.x deployments; AR versions prior to 6.0 ship with SDM available and require explicit deactivation in the Automation Studio project. ABB also recommends configuring the AR webserver to require HTTPS, enabling mutual TLS ('Validate SSL communication partner') in Automation Studio, and restricting the webserver TCP listener to trusted IP ranges using the Automation Runtime host-based firewall. None of these compensating controls is a substitute for patching: a properly-segmented but enabled SDM endpoint is still vulnerable to anyone with engineering-network access (insider threat, lateral movement from a compromised HMI/engineering workstation, or VPN intrusion).

Exploit chain (theoretical, from advisory text):
1) Reconnaissance — attacker scans the OT network for AR webserver instances, identified by characteristic HTTP/HTTPS banners on default or operator-configured ports and the presence of the SDM URL path.
2) Initial Access — attacker connects to the AR webserver from any reachable host (engineering workstation foothold, compromised HMI, mis-segmented IT/OT bridge, or directly exposed control system).
3) Execution — attacker issues a specially crafted HTTP(S) request sequence to the SDM endpoint that triggers the improper-locking condition in AR's diagnostic data structures.
4) Impact — the locking flaw causes SDM-managed data to be deleted and the controller process to halt. The affected B&R system node stops, which in ICS contexts typically translates into a stopped scan cycle, loss of view/loss of control for HMI/SCADA operators, and potentially a safe-state trip of downstream physical equipment depending on watchdog and safety-instrumented system configuration.

Detection-relevant artefacts on networks running AR include: unusual HTTP/HTTPS requests to SDM URLs from non-engineering hosts; sudden controller cyclic-task termination events surfaced via OPC UA / mapp Services telemetry; AR webserver process restarts; loss-of-comms alarms in SCADA against B&R PLC IPs. Mitigations recommended by ABB: upgrade to AR 6.3 / Q4.93; disable SDM where not required; enforce HTTPS + mTLS for the AR webserver; restrict the webserver to trusted IPs via the AR host-based firewall; segment OT from IT; restrict engineering-network access to authorised maintenance personnel and time windows.

## MITRE ATT&CK

- T1595 Active Scanning
- T1595.002 Active Scanning: Vulnerability Scanning
- T1590 Gather Victim Network Information
- T1592.002 Gather Victim Host Information: Software
- T1587.004 Develop Capabilities: Exploits
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1203 Exploitation for Client Execution
- T1046 Network Service Discovery
- T1082 System Information Discovery
- T1499 Endpoint Denial of Service
- T1499.003 Endpoint Denial of Service: Application Exhaustion Flood
- T1499.004 Endpoint Denial of Service: Application or System Exploitation
- T1489 Service Stop
- T1485 Data Destruction
- T1529 System Shutdown/Reboot

## Sources

- [CISA ICS Advisory ICSA-26-146-04 — ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)](https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-04)
- [ABB PSIRT Security Advisory SA25P002 (vendor PDF)](https://www.br-automation.com/fileadmin/SA25P002-f6a69e61.pdf)
- [NVD — CVE-2025-3450](https://nvd.nist.gov/vuln/detail/CVE-2025-3450)
- [MITRE CWE-413: Improper Resource Locking](https://cwe.mitre.org/data/definitions/413.html)
- [B&R Automation Runtime product page](https://www.br-automation.com/en/products/software/automation-runtime/)
- [CISA — Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies](https://www.cisa.gov/resources-tools/resources/improving-industrial-control-systems-cybersecurity-defense-depth-strategies)
- [CISA ICS-TIP-12-146-01B — Targeted Cyber Intrusion Detection and Mitigation Strategies](https://www.cisa.gov/news-events/ics-tips/ics-tip-12-146-01b)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0593
