CVE-2025-3450: Automation Runtime SDM requests may impact system
Published Oct 7, 2025
·Updated
An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.
Affected Software
1 affected component
B&R Automation Automation Runtime<6.3, <Q4.93
Event History
Oct 7, 2025
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3450?
CVE-2025-3450 has been classified as a high-severity vulnerability due to improper resource locking.
2
How do I fix CVE-2025-3450?
To fix CVE-2025-3450, upgrade your Automation Runtime to version 6.3 or later, or Q4.93 or later.
3
Which versions are affected by CVE-2025-3450?
CVE-2025-3450 affects Automation Runtime versions from 6.0 before 6.3, and before Q4.93.
4
What are the consequences of CVE-2025-3450?
CVE-2025-3450 can lead to unauthorized access and manipulation of resources due to improper locking.
5
Who is primarily affected by CVE-2025-3450?
Businesses using affected versions of B&R Industrial Automation Automation Runtime are primarily impacted by CVE-2025-3450.