PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-11482 B&R Industrial Automation GmbH CVE debrief

A resource exhaustion vulnerability in the OPC-UA Server component of PPT30 Operating System versions prior to 1.8.0 allows unauthenticated network-based attackers to cause permanent denial of service. The flaw, classified as CWE-770 (Allocation of Resources Without Limits or Throttling), enables attackers to exhaust server resources in a way that prevents legitimate users from accessing the service indefinitely. The vulnerability carries a HIGH severity CVSS 4.0 score of 8.7, reflecting significant availability impact with no confidentiality or integrity compromise. The affected product appears to be industrial control system software, with the vendor contact email suggesting ABB as the responsible party. No known exploitation in the wild or ransomware campaign use has been documented.

Vendor
B&R Industrial Automation GmbH
Product
PPT30 Operating System
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-06-04
Advisory published
2026-05-26
Advisory updated
2026-06-04

Who should care

Organizations operating PPT30 industrial control systems, critical infrastructure operators using OPC-UA communications, OT security teams, and asset owners in manufacturing, energy, or process industries where PPT30 is deployed

Technical summary

The OPC-UA Server in PPT30 Operating System versions before 1.8.0 fails to implement proper resource limits or throttling mechanisms. An unauthenticated attacker can exploit this weakness by sending crafted network requests that consume excessive server resources, resulting in permanent service unavailability for legitimate users. The attack requires no privileges, no user interaction, and is exploitable over the network with low attack complexity. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H) confirms network attack vector with high availability impact and no confidentiality or integrity effects.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade PPT30 Operating System to version 1.8.0 or later to remediate the vulnerability
  • Implement network segmentation to restrict OPC-UA Server access to authorized systems only
  • Deploy rate limiting and connection throttling at network perimeter for OPC-UA services
  • Monitor for anomalous connection patterns or resource exhaustion indicators on OPC-UA Server instances
  • Review and apply vendor security advisory SA25P006 for additional mitigation guidance

Evidence notes

Vulnerability description and CVSS vector sourced from NVD record. Vendor attribution inferred from contact email '[email protected]' in source references with low confidence requiring review. CPE criteria not yet populated in source data.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-11482 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-11482

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-11482 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11482

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.