Executive Summary
In October 2025, ABB B&R Automation Runtime versions prior to 6.4 were found to have multiple vulnerabilities, including CVE-2025-3449, CVE-2025-3448, and CVE-2025-11498. These flaws could allow unauthenticated attackers to hijack sessions, execute arbitrary JavaScript in users' browsers, and inject malicious formulas into CSV files. Exploitation required network access and user interaction, posing significant risks to industrial control systems.
The discovery of these vulnerabilities underscores the critical need for robust security measures in industrial automation environments. As cyber threats targeting operational technology increase, organizations must prioritize timely updates and comprehensive security practices to safeguard against potential exploits.
Why This Matters Now
The identification of these vulnerabilities highlights the urgent need for organizations to update their systems to the latest versions and implement stringent security protocols to protect against evolving cyber threats targeting industrial control systems.
Attack Path Analysis
An attacker exploits predictable session identifiers in the System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 to hijack an active session. Upon gaining access, the attacker escalates privileges by injecting malicious scripts through reflected cross-site scripting (XSS) vulnerabilities, executing arbitrary JavaScript in the context of the user's browser session. The attacker then moves laterally within the network by exploiting the compromised session to access other systems. Establishing command and control, the attacker uses the compromised systems to maintain persistent access and control. Sensitive data is exfiltrated by leveraging the compromised systems to transfer data to external servers. Finally, the attacker impacts the organization by potentially disrupting operations or causing data loss.
Kill Chain Progression
Initial Compromise
Description
An attacker exploits predictable session identifiers in the System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 to hijack an active session.
Related CVEs
CVE-2025-3449
CVSS 4.2A vulnerability in the System Diagnostics Manager (SDM) component of B&R Automation Runtime versions before 6.4 allows an unauthenticated network-based attacker to take over already established sessions.
Affected Products:
B&R Automation Runtime – <6.4
Exploit Status:
no public exploitCVE-2025-3448
CVSS 6.1Reflected cross-site scripting (XSS) vulnerabilities in the SDM component of B&R Automation Runtime versions before 6.4 enable a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.
Affected Products:
B&R Automation Runtime – <6.4
Exploit Status:
no public exploitCVE-2025-11498
CVSS 6.1An improper neutralization of formula elements in a CSV file vulnerability exists in the SDM component of B&R Automation Runtime versions before 6.4, enabling a remote attacker to inject formula data into a generated CSV file.
Affected Products:
B&R Automation Runtime – <6.4
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Drive-by Compromise
JavaScript
Exploitation for Client Execution
Spearphishing Attachment
Spearphishing Link
Exploit Public-Facing Application
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Applications and Workloads
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
ABB B&R Automation Runtime vulnerabilities enable session hijacking and XSS attacks on manufacturing control systems, requiring immediate patching of versions before 6.4.
Oil/Energy/Solar/Greentech
Critical infrastructure energy systems using B&R automation face remote exploitation risks through predictable session IDs and cross-site scripting in diagnostic interfaces.
Utilities
Power grid and utility control systems vulnerable to browser-based attacks and CSV injection through compromised System Diagnostics Manager interfaces in automation runtime.
Automotive
Manufacturing automation systems running vulnerable B&R Runtime expose production lines to remote code execution and session takeover attacks via web interfaces.
Sources
- ABB B&R Automation Runtimehttps://www.cisa.gov/news-events/ics-advisories/icsa-26-141-04Verified
- CVE-2025-3449 Detail | NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-3449Verified
- CVE-2025-3448 Detail | NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-3448Verified
- CVE-2025-11498 Detail | NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-11498Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit predictable session identifiers may be constrained by enforcing strict access controls and monitoring session behaviors.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges through XSS may be limited by restricting access to sensitive resources based on strict segmentation policies.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network could likely be restricted by enforcing east-west traffic controls and monitoring.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control may be constrained by comprehensive visibility and control across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could likely be limited by enforcing strict egress security policies.
The attacker's potential to disrupt operations or cause data loss may be reduced by limiting their access and movement within the network.
Impact at a Glance
Affected Business Functions
- System Diagnostics
- Remote Monitoring
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of diagnostic data and user session information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Cloud Firewall (ACF) to control and monitor outbound traffic, preventing unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch systems to mitigate known vulnerabilities and reduce the attack surface.



