B&R PPT30 Operating System
A vulnerability, CVE-2025-11482, has been identified in B&R PPT30 Operating System versions prior to 1.8.0, specifically within the OPC-UA Server. An unauthenticated network-based attacker could exploit this flaw to permanently block legitimate users from accessing the OPC-UA server, potentially impacting critical infrastructure systems. B&R has released a fix, and customers are advised to update their systems promptly to mitigate the risk.
This security advisory from CISA details a critical vulnerability affecting B&R PPT30 Operating System. The vulnerability, classified as CWE-770 (Allocation of Resources Without Limits or Throttling), resides within the OPC-UA Server component. An attacker with network access could leverage this flaw to persistently prevent authorized users from interacting with the OPC-UA server, effectively disrupting operations. The vulnerability is triggered by an unauthenticated network-based attacker sending messages to an affected system node. This highlights the importance of network segmentation and firewall configurations to limit potential attack vectors.
The affected products include B&R PPT30 Operating System versions prior to 1.8.0. The vulnerability impacts sectors such as Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems, and Water and Wastewater. B&R recommends that customers with the OPC-UA Server enabled install the update at their earliest opportunity, alongside implementing recommended mitigation strategies such as restricting access to the OPC-UA server exclusively to trusted IP addresses and ensuring proper network segmentation. ABB PSIRT reported this vulnerability to CISA, demonstrating a collaborative approach to cybersecurity.
B&R has provided a vendor fix and detailed remediation steps within the user manual. The advisory emphasizes the need for proactive security measures to protect systems utilizing the PPT30 Operating System.