CVE-2025-11498: CSV Formula Injection Vulnerability
An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a malicious link. The user would need to click on this link, after which the resulting CSV file addi-tionally needs to be manually opened.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11498?
CVE-2025-11498 has a high severity rating due to the potential for remote code execution via CSV file injection.
How do I fix CVE-2025-11498?
To fix CVE-2025-11498, upgrade B&R Automation Runtime to version 6.4 or later, which addresses this vulnerability.
What products are affected by CVE-2025-11498?
CVE-2025-11498 affects B&R Automation Runtime versions prior to 6.4.
Can CVE-2025-11498 be exploited remotely?
Yes, CVE-2025-11498 can be exploited remotely by attackers to inject malicious formula data into CSV files.
What types of attacks are possible with CVE-2025-11498?
Exploitation of CVE-2025-11498 can lead to unauthorized command execution through manipulated CSV files.