A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Br-automation
Br-automation automation Runtime |
|
Vendors & Products |
Br-automation
Br-automation automation Runtime |
Wed, 08 Oct 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Generation of Predictable Numbers or Identifiers vulnerability in B&R Industrial Automation Automation Runtime.This issue affects Automation Runtime: from 6.0 before 6.4. | A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions. |
Tue, 07 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Oct 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Generation of Predictable Numbers or Identifiers vulnerability in B&R Industrial Automation Automation Runtime.This issue affects Automation Runtime: from 6.0 before 6.4. | |
Title | Weak Session Token used in Automation Runtime SDM | |
Weaknesses | CWE-340 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ABB
Published: 2025-10-07T18:21:32.231Z
Updated: 2025-10-08T13:15:41.649Z
Reserved: 2025-04-08T14:10:00.516Z
Link: CVE-2025-3449

Updated: 2025-10-07T18:48:18.807Z

Status : Received
Published: 2025-10-07T19:15:36.620
Modified: 2025-10-08T14:15:41.683
Link: CVE-2025-3449

No data.