CVE-2025-11044: Vulnerability on Automation Runtime my cause DoS Conditions
An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on affected devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11044?
CVE-2025-11044 is a moderate severity vulnerability that can lead to Denial of Service (DoS) conditions.
How does CVE-2025-11044 affect B&R Automation Runtime?
CVE-2025-11044 affects B&R Automation Runtime versions prior to 6.5 and R4.93, allowing unauthenticated attackers to exploit resource allocation issues.
How do I fix CVE-2025-11044?
To fix CVE-2025-11044, upgrade your B&R Automation Runtime to version 6.5 or R4.93 or later.
Who can exploit CVE-2025-11044?
CVE-2025-11044 can be exploited by any unauthenticated attacker on the same network.
What component of B&R Automation is affected by CVE-2025-11044?
CVE-2025-11044 specifically affects the ANSL-Server component of B&R Automation Runtime.