ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
CISA says an unauthenticated attacker could crash ABB B&R Automation Runtime by abusing SDM, with fixes in versions 6.3 and Q4.93.
Intelligence analysis by GPT-5.4 Mini
CISA details a critical denial-of-service flaw in the System Diagnostics Manager component of ABB B&R Automation Runtime. The advisory says unauthenticated network attackers could trigger data deletion and stop the product, and recommends patching or disabling SDM.
A piece of software that helps check a machine’s health has a flaw. If the wrong person reaches it over the network, they may be able to make it stop working.
Think of it like a building’s alarm panel that can be messed with from outside. If the lock on that panel is weak, someone could cause trouble without even walking in.
The fix is to update to the repaired versions and keep the diagnostic tool turned off or tightly guarded unless it is truly needed.
Analysis
What CISA says
CISA released an ICS advisory for an improper resource locking vulnerability in the System Diagnostics Manager (SDM) component of ABB B&R Automation Runtime. The advisory says an unauthenticated network-based attacker could delete data and force a denial of service condition, potentially stopping the product.
Scope and severity
The affected versions listed are Automation Runtime versions before 6.3 and before Q4.93. CISA assigns the issue CVE-2025-3450 and a CVSS v3.1 base score of 10.0, marking it critical. The advisory says the issue was identified by B&R’s internal security analysis and reported to CISA by ABB PSIRT.
Fixes and mitigations
B&R says the problem is corrected in Automation Runtime 6.3 and Q4.93. The advisory also notes that SDM is disabled by default in Automation Runtime 6 and is not intended to be enabled on active systems outside properly secured production networks or facilities without strong physical and logical access controls.
For sites that still use SDM, the guidance is to apply the update as soon as practical, restrict SDM to trusted personnel, and enable it only for the minimum time needed for maintenance. The page also recommends using HTTPS, mutual TLS where appropriate, and host-based firewall rules to limit access to trusted IP addresses.
Operational context
CISA lists deployment across multiple critical infrastructure sectors, including chemical, communications, critical manufacturing, dams, energy, healthcare and public health, information technology, and water and wastewater. That makes the flaw relevant beyond one vendor’s product line, especially for operators who treat runtime diagnostics as part of normal maintenance workflows.
Key points
- CISA says SDM in ABB B&R Automation Runtime can be abused for denial of service.
- The issue is CVE-2025-3450 and carries a CVSS v3.1 score of 10.0.
- Affected versions are Automation Runtime before 6.3 and before Q4.93.
- B&R says the bug is fixed in Automation Runtime 6.3 and Q4.93.
- Mitigations include disabling SDM, restricting access, and using HTTPS, mTLS, and firewall rules.



