A resource-exhaustion vulnerability in B&R's PPT30 Operating System lets an unauthenticated attacker knock its OPC-UA server offline — no credentials required.
The flaw, tracked as CVE-2025-11482 and scored 7.5 (High) on the CVSS 3.1 scale, affects all PPT30 OS versions before 1.8.0. An attacker with network access can flood the OPC-UA server with messages, exhausting its resources and permanently blocking legitimate connections. The fix ships in version 1.8.0. ABB's PSIRT, which shares a parent company with B&R, discovered and reported the issue to CISA — an internal find, not an outside researcher or active exploit report.
The PPT30 is industrial firmware used in sectors where downtime is expensive and sometimes dangerous: energy, transportation, water treatment, and critical manufacturing. A denial-of-service against an OPC-UA server — the standard protocol layer that lets supervisory systems talk to plant equipment — could silence the visibility operators depend on to catch process failures. That said, the OPC-UA server is off by default, and B&R's own architecture guidance places PPT30 devices behind network segmentation and firewalls; a reachable, unpatched unit represents a configuration failure as much as a software one.
The recurring lesson of ICS security advisories is that air-gap assumptions erode over time: maintenance VPNs, flat corporate-OT networks, and misconfigured firewalls keep putting "isolated" equipment within reach. Patch to 1.8.0, and if you genuinely need OPC-UA enabled, double-check what can actually reach port 4840.
