CISA warns of DoS vulnerability in ABB automation systems

Critical infrastructure operators urged to patch ABB B&R Automation Runtime after disclosure of unauthenticated network attack vector.

Illustration: CISA warns of DoS vulnerability in ABB automation systems

Critical infrastructure operators urged to patch ABB B&R Automation Runtime after disclosure of unauthenticated network attack vector.

  • CVE-2025-3450 affects ABB B&R Automation Runtime versions before 6.3 and Q4.93
  • Unauthenticated attackers can cause denial of service by deleting data through System Diagnostics Manager
  • Patches available for affected versions with SDM disabled by default in newer releases

CISA has issued an advisory warning operators of critical infrastructure about a denial of service vulnerability in ABB B&R Automation Runtime systems used across multiple sectors including energy, manufacturing and healthcare.

The vulnerability, tracked as CVE-2025-3450, affects the System Diagnostics Manager (SDM) component in Automation Runtime versions before 6.3 and before Q4.93. An unauthenticated network-based attacker can exploit improper resource locking to delete data and cause denial of service conditions.

ABB B&R’s automation systems are deployed worldwide and support critical infrastructure operations in chemical facilities, energy systems, water treatment plants and manufacturing operations. The Swiss-based vendor discovered the vulnerability through internal security analysis.

The issue stems from improper resource locking in the SDM component, which allows attackers to manipulate system data without authentication. Successful exploitation could force affected automation systems to stop operating, potentially disrupting industrial processes.

ABB has released patches addressing the vulnerability in Automation Runtime versions 6.3 and Q4.93. The company has also modified its security posture by disabling SDM by default in Automation Runtime 6 releases.

According to the CISA advisory, ABB recommends that customers using SDM should not enable it on systems located outside properly secured production networks or in facilities lacking adequate physical and logical access controls.

Why It Matters

This vulnerability presents significant operational risk for organisations running critical infrastructure with affected ABB automation systems. The unauthenticated attack vector means any network access to vulnerable systems could result in service disruption. For CISOs overseeing industrial control systems, this represents a clear example of why operational technology security requires the same rigorous patch management discipline as traditional IT systems.

Given the widespread deployment of ABB systems across critical sectors, this vulnerability could impact business continuity and safety systems. Boards will want assurance that industrial control system vulnerabilities are tracked and remediated with appropriate urgency.

What To Do Now

  • Inventory ABB B&R Automation Runtime systems and identify versions before 6.3 and Q4.93 according to the CISA advisory
  • Apply vendor patches to update affected systems to Automation Runtime versions 6.3 or Q4.93 as recommended by ABB
  • Disable System Diagnostics Manager on systems outside secured production networks per vendor guidance
  • Review network segmentation and access controls for industrial control systems housing ABB automation equipment

Sources