CVE-2025-3450Active Exploitation

LOWCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-413

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-26: 2Active Exploitation · 2026-05-26: 2Technical Details · 2026-05-26: 205-26
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-3450 can trigger denial-of-service conditions in ABB B&R Automation Runtime without authentication. The improper resource locking vulnerability allows unauthorized data deletion in critical industrial systems. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/icsa-26-146-04-abb-br-automation-runtime-dos-vulnerability

    Post summary

    The post reports attackers are actively exploiting CVE-2025-3450 to cause DoS and unauthorized data deletion in ABB B&R Automation Runtime, with no PoC or patch details provided.

    10000132
    1.9K followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: ABB B&R AR SDM (CVE-2025-3450) - unauth DoS halts PLCs, CVSS 10.0, 8 ICS sectors. 9 detections, 12 IOCs. https://intel.threadlinqs.com/threat/TL-2026-0593 #ThreatIntel #ICS https://t.co/SkZNpGC331

    Post summary

    This threat intel release confirms that CVE-2025-3450, a critical unauthenticated denial‑of‑service weakness in ABB B&R AR SDM, has been actively exploited, with nine detections and twelve IOCs reported in the industrial control sector.

    00000138
    51 followersView on X

Explore more