CISA warns of session takeover flaws in ABB automation systems

Three vulnerabilities in B&R Automation Runtime could allow attackers to hijack sessions and execute malicious code in industrial environments.

Illustration: CISA warns of session takeover flaws in ABB automation systems

Three vulnerabilities in B&R Automation Runtime could allow attackers to hijack sessions and execute malicious code in industrial environments.

  • CISA issued advisory for three vulnerabilities in ABB B&R Automation Runtime versions before 6.4
  • Flaws could enable session takeover and cross-site scripting attacks on industrial control systems
  • Patches available in version 6.4, with System Diagnostic Manager disabled by default

The US Cybersecurity and Infrastructure Security Agency has issued an advisory warning of three vulnerabilities in ABB’s B&R Automation Runtime that could allow attackers to take control of remote sessions and execute code in users’ browser sessions.

The vulnerabilities affect Automation Runtime versions before 6.4, which are deployed worldwide in energy sector critical infrastructure. ABB, headquartered in Switzerland, has released patches in version 6.4 to address all three flaws.

The most critical vulnerability, CVE-2025-3449, carries a CVSS score of 6.1 and stems from predictable number generation in the System Diagnostic Manager component. An unauthenticated network-based attacker could exploit this flaw to hijack established user sessions.

The other two vulnerabilities, CVE-2025-3448 and CVE-2025-11498, involve cross-site scripting weaknesses and improper handling of formula elements in CSV files. Together, these flaws could enable attackers to execute malicious code within the context of a user’s browser session.

ABB discovered the vulnerabilities through internal security analysis. The company notes that the System Diagnostic Manager is disabled by default in Automation Runtime 6 and should not be enabled on systems outside properly secured production networks.

For organisations that do use the System Diagnostic Manager, ABB recommends applying the update based on risk assessment at the earliest opportunity. The vendor has provided installation procedures and version identification steps in the product’s user manual.

The advisory highlights ongoing security challenges in industrial control systems, where legacy components and network architectures can create attack vectors for both authenticated and unauthenticated threats.

Why It Matters

Industrial control system vulnerabilities pose significant operational and safety risks that require immediate CISO attention. These ABB flaws could enable attackers to manipulate critical infrastructure systems in the energy sector, potentially causing service disruptions or safety incidents.

The combination of session hijacking and code execution capabilities means attackers could gain persistent access to industrial networks. CISOs should prioritise patching these systems and review network segmentation controls for industrial environments.

What To Do Now

  • Inventory all ABB B&R Automation Runtime systems and identify versions before 6.4 requiring updates
  • Apply the Automation Runtime 6.4 patches based on operational risk assessment
  • Ensure System Diagnostic Manager remains disabled unless absolutely required for operations
  • Review network segmentation between industrial control systems and corporate networks

Sources