CNNVD-202510-911 Information

CNNVD ID

CNNVD-202510-911

CVE-2025-3449

  • CNNVD Published: 2025-10-07

Description (Chinese)

B&R Automation Runtime是B&R Automation公司的一个自动化运行时。 B&R Automation Runtime 6.4之前版本存在安全漏洞,该漏洞源于SDM组件生成可预测数字或标识符,可能导致未经身份验证的网络攻击者接管已建立的会话。

Description (English)

B&R Automation Runtme is an automated running time for B&R Automation. Prior to the version of B&R Automation Runtime 6.4, there was a security loophole, which originated from the generation of predictable numbers or identifiers for SDMX components, which could lead to unidentified cyber assailants taking over established sessions.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

B&R Automation

Published

2025-10-07

Last Modified

2026-02-24

References

https://www.br-automation.com/fileadmin/SA25P003-178b6a20.pdf

Patch

https://www.br-automation.com/fileadmin/SA25P003-178b6a20.pdf

Share on: