216.73.217.98

CVE-2025-3449

· Published 07/10/2025 19:15 · Modified 08/10/2025 19:38

Labels: CVE-2025-3449 2025-10-07CVE-2025-3449CWE-340[email protected]

Essential information

Published
07/10/2025 19:15
Modified
08/10/2025 19:38
Author
Creator
CVSS
2.3 LOW (v3) 2.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
br industrial automation / automation runtime cpe:2.3:a:br_industrial_automation:automation_runtime:6.0-6.4:*:*:*:*:*:*:*

References