B&R PPT30 Operating System
CISA says B&R's PPT30 Operating System has a high-severity OPC-UA server flaw that can make the service unavailable.
Intelligence analysis by GPT-5.4 Mini
The advisory covers a denial-of-service weakness in the PPT30 Operating System's OPC-UA server, affecting versions before 1.8.0 and 1.8.0 itself. B&R says version 1.8.0 fixes the issue and recommends updating or keeping the optional server disabled unless needed.
A part of this industrial computer can get overloaded by bad messages, like a mailbox stuffed until nobody can use it. The fix is to update it and keep the extra service turned off unless it is truly needed.
Analysis
CISA's advisory describes a vulnerability in B&R Industrial Automation's PPT30 Operating System, specifically in the OPC-UA server component. The affected versions are listed as PPT30 Operating System less than 1.8.0 and 1.8.0, with the issue tracked as CVE-2025-11482.
The flaw is an allocation-of-resources problem: an unauthenticated network-based attacker could use it to make the OPC-UA server inaccessible. In practical terms, that means legitimate users may no longer be able to connect to the service on impacted devices. The advisory rates the issue 7.5 high on CVSS v3.1, with network attack vector, low complexity, no privileges required, and no user interaction needed.
B&R says version 1.8.0 corrects the problem. The company also notes that the OPC-UA server is not enabled by default, and recommends installing the update as soon as possible if the server is enabled. The mitigation guidance is straightforward: only turn on the optional server if it is required, restrict access to trusted IP addresses through the South Firewall or Control Network Firewall, segment the network, and ensure the relevant physical interfaces are only reachable by authorized personnel.
The advisory places PPT30 systems in Levels 1 and 2 of the ABB ICS Cyber Security Reference Architecture and lists deployment across commercial facilities, critical manufacturing, energy, transportation systems, and water and wastewater sectors. CISA also notes that ABB PSIRT reported the vulnerability to CISA, and the FAQ says B&R discovered it through its own security analysis.
Key points
- CISA says B&R PPT30 Operating System has a high-severity OPC-UA server vulnerability.
- The issue affects versions before 1.8.0 and also 1.8.0 as listed in the advisory.
- An unauthenticated network attacker could make the OPC-UA server inaccessible.
- B&R says version 1.8.0 fixes the problem and recommends updating quickly if the server is enabled.
- Mitigations include keeping the server off unless needed and limiting access to trusted IP addresses.
If customers install version 1.8.0 and keep the OPC-UA server disabled unless necessary, the vulnerable path can be closed off. The network restrictions B&R recommends could also reduce exposure in plants that need the service turned on.
If the update is not applied, an attacker with network access could still knock the OPC-UA server offline and block legitimate users. Misconfigured firewalls or weak network segmentation would make that easier to reach in connected industrial environments.



