CVE-2025-3449: Weak Session Token used in Automation Runtime SDM
A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3449?
CVE-2025-3449 is classified as a high severity vulnerability due to the potential for predictable number or identifier generation.
How do I fix CVE-2025-3449?
To fix CVE-2025-3449, upgrade your Automation Runtime software to version 6.4 or higher.
Which versions of B&R Industrial Automation Automation Runtime are affected by CVE-2025-3449?
CVE-2025-3449 affects B&R Industrial Automation Automation Runtime versions from 6.0 up to, but not including, 6.4.
What type of vulnerability is CVE-2025-3449?
CVE-2025-3449 is a vulnerability related to the generation of predictable numbers or identifiers.
Is there a workaround for CVE-2025-3449?
No specific workaround has been published for CVE-2025-3449, so upgrading to a safe version is recommended.