news.mlab.sh
Back to the feed
vulnerability

B&R PPT30 Operating System

High
Summary

A vulnerability, CVE-2025-11482, has been identified in B&R PPT30 Operating System versions prior to 1.8.0, specifically within the OPC-UA Server. An unauthenticated network-based attacker could exploit this flaw to permanently block legitimate users from accessing the OPC-UA server, potentially impacting critical infrastructure systems. B&R has released a fix, and customers are advised to update their systems promptly to mitigate the risk.

This security advisory from CISA details a critical vulnerability affecting B&R PPT30 Operating System. The vulnerability, classified as CWE-770 (Allocation of Resources Without Limits or Throttling), resides within the OPC-UA Server component. An attacker with network access could leverage this flaw to persistently prevent authorized users from interacting with the OPC-UA server, effectively disrupting operations. The vulnerability is triggered by an unauthenticated network-based attacker sending messages to an affected system node. This highlights the importance of network segmentation and firewall configurations to limit potential attack vectors.

The affected products include B&R PPT30 Operating System versions prior to 1.8.0. The vulnerability impacts sectors such as Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems, and Water and Wastewater. B&R recommends that customers with the OPC-UA Server enabled install the update at their earliest opportunity, alongside implementing recommended mitigation strategies such as restricting access to the OPC-UA server exclusively to trusted IP addresses and ensuring proper network segmentation. ABB PSIRT reported this vulnerability to CISA, demonstrating a collaborative approach to cybersecurity.

B&R has provided a vendor fix and detailed remediation steps within the user manual. The advisory emphasizes the need for proactive security measures to protect systems utilizing the PPT30 Operating System.

Read the full article at CISA Advisories