PatchSiren cyber security CVE debrief
CVE-2025-11482 B&R Industrial Automation GmbH CVE debrief
A resource exhaustion vulnerability in the OPC-UA Server component of PPT30 Operating System versions prior to 1.8.0 allows unauthenticated network-based attackers to cause permanent denial of service. The flaw, classified as CWE-770 (Allocation of Resources Without Limits or Throttling), enables attackers to exhaust server resources in a way that prevents legitimate users from accessing the service indefinitely. The vulnerability carries a HIGH severity CVSS 4.0 score of 8.7, reflecting significant availability impact with no confidentiality or integrity compromise. The affected product appears to be industrial control system software, with the vendor contact email suggesting ABB as the responsible party. No known exploitation in the wild or ransomware campaign use has been documented.
- Vendor
- B&R Industrial Automation GmbH
- Product
- PPT30 Operating System
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-06-04
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-06-04
Who should care
Organizations operating PPT30 industrial control systems, critical infrastructure operators using OPC-UA communications, OT security teams, and asset owners in manufacturing, energy, or process industries where PPT30 is deployed
Technical summary
The OPC-UA Server in PPT30 Operating System versions before 1.8.0 fails to implement proper resource limits or throttling mechanisms. An unauthenticated attacker can exploit this weakness by sending crafted network requests that consume excessive server resources, resulting in permanent service unavailability for legitimate users. The attack requires no privileges, no user interaction, and is exploitable over the network with low attack complexity. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H) confirms network attack vector with high availability impact and no confidentiality or integrity effects.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade PPT30 Operating System to version 1.8.0 or later to remediate the vulnerability
- Implement network segmentation to restrict OPC-UA Server access to authorized systems only
- Deploy rate limiting and connection throttling at network perimeter for OPC-UA services
- Monitor for anomalous connection patterns or resource exhaustion indicators on OPC-UA Server instances
- Review and apply vendor security advisory SA25P006 for additional mitigation guidance
Evidence notes
Vulnerability description and CVSS vector sourced from NVD record. Vendor attribution inferred from contact email '[email protected]' in source references with low confidence requiring review. CPE criteria not yet populated in source data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-11482 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-11482
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-11482 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11482
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://br-cws-assets.de-fra-1.linodeobjects.com/SA25P006-0eec719c.pdf
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.