The Containment Era is here. →Explore

Executive Summary

In October 2025, ABB identified a critical vulnerability (CVE-2025-3450) in the System Diagnostics Manager (SDM) component of B&R Automation Runtime versions prior to 6.3 and Q4.93. This flaw allows unauthenticated, network-based attackers to delete data, leading to denial-of-service conditions. The vulnerability stems from improper resource locking within the SDM, potentially causing affected systems to cease operation upon exploitation. ABB has released updates to address this issue and recommends users upgrade to Automation Runtime versions 6.3 or Q4.93 to mitigate the risk. This incident underscores the importance of timely patch management and robust network security practices, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.

Why This Matters Now

The discovery of CVE-2025-3450 highlights the ongoing challenges in securing industrial control systems against network-based attacks. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize the implementation of security updates and adhere to best practices to safeguard their operations from potential disruptions.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

CVE-2025-3450 is a critical vulnerability in the System Diagnostics Manager component of ABB's B&R Automation Runtime, allowing unauthenticated attackers to delete data and cause denial-of-service conditions.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit the SDM vulnerability, thereby reducing the potential for unauthorized data deletion and system disruption.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit the SDM vulnerability would likely have been constrained, reducing the potential for unauthorized data deletion and system disruption.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges would likely have been constrained, reducing the potential for unauthorized data deletion and system disruption.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the network would likely have been constrained, reducing the potential for unauthorized data deletion and system disruption.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish and maintain command and control channels would likely have been constrained, reducing the potential for unauthorized data deletion and system disruption.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate data would likely have been constrained, reducing the potential for unauthorized data deletion and system disruption.

Impact (Mitigations)

The attacker's ability to cause a denial of service condition would likely have been constrained, reducing the potential for unauthorized data deletion and system disruption.

Impact at a Glance

Affected Business Functions

  • Industrial Control Systems Operations
  • Manufacturing Process Control
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

n/a

Recommended Actions

  • Implement Zero Trust Segmentation to restrict access to critical components like the SDM, ensuring only authorized entities can interact with them.
  • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities, such as improper resource locking issues.
  • Utilize Multicloud Visibility & Control to monitor and manage network traffic, identifying unauthorized access attempts and potential command and control channels.
  • Enforce Egress Security & Policy Enforcement to control outbound traffic, preventing unauthorized data deletion commands from being executed remotely.
  • Regularly update and patch systems to address known vulnerabilities, reducing the attack surface available to potential attackers.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image