PatchSiren cyber security CVE debrief
CVE-2025-11482 B&R Industrial Automation GmbH CVE debrief
A resource exhaustion vulnerability in the OPC-UA Server component of PPT30 Operating System versions prior to 1.8.0 allows unauthenticated network-based attackers to cause permanent denial of service. The flaw, classified as CWE-770 (Allocation of Resources Without Limits or Throttling), enables attackers to exhaust server resources in a way that prevents legitimate users from accessing the service indefinitely. The vulnerability carries a HIGH severity CVSS 4.0 score of 8.7, reflecting significant availability impact with no confidentiality or integrity compromise. The affected product appears to be industrial control system software, with the vendor contact email suggesting ABB as the responsible party. No known exploitation in the wild or ransomware campaign use has been documented.
- Vendor
- B&R Industrial Automation GmbH
- Product
- PPT30 Operating System
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations operating PPT30 industrial control systems, critical infrastructure operators using OPC-UA communications, OT security teams, and asset owners in manufacturing, energy, or process industries where PPT30 is deployed
Technical summary
The OPC-UA Server in PPT30 Operating System versions before 1.8.0 fails to implement proper resource limits or throttling mechanisms. An unauthenticated attacker can exploit this weakness by sending crafted network requests that consume excessive server resources, resulting in permanent service unavailability for legitimate users. The attack requires no privileges, no user interaction, and is exploitable over the network with low attack complexity. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H) confirms network attack vector with high availability impact and no confidentiality or integrity effects.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade PPT30 Operating System to version 1.8.0 or later to remediate the vulnerability
- Implement network segmentation to restrict OPC-UA Server access to authorized systems only
- Deploy rate limiting and connection throttling at network perimeter for OPC-UA services
- Monitor for anomalous connection patterns or resource exhaustion indicators on OPC-UA Server instances
- Review and apply vendor security advisory SA25P006 for additional mitigation guidance
Evidence notes
Vulnerability description and CVSS vector sourced from NVD record. Vendor attribution inferred from contact email '[email protected]' in source references with low confidence requiring review. CPE criteria not yet populated in source data.
Official resources
-
CVE-2025-11482 CVE record
CVE.org
-
CVE-2025-11482 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-26