Security/ ics security · ot security · vulnerability · industrial control systems

A DoS Flaw in B&R Industrial OS Puts OPC-UA Servers at Risk

An unauthenticated attacker with network access can permanently lock legitimate users out of the OPC-UA server on unpatched B&R PPT30 devices.

A DoS Flaw in B&R Industrial OS Puts OPC-UA Servers at Risk

A resource-exhaustion vulnerability in B&R's PPT30 Operating System lets an unauthenticated attacker knock its OPC-UA server offline — no credentials required.

The flaw, tracked as CVE-2025-11482 and scored 7.5 (High) on the CVSS 3.1 scale, affects all PPT30 OS versions before 1.8.0. An attacker with network access can flood the OPC-UA server with messages, exhausting its resources and permanently blocking legitimate connections. The fix ships in version 1.8.0. ABB's PSIRT, which shares a parent company with B&R, discovered and reported the issue to CISA — an internal find, not an outside researcher or active exploit report.

The PPT30 is industrial firmware used in sectors where downtime is expensive and sometimes dangerous: energy, transportation, water treatment, and critical manufacturing. A denial-of-service against an OPC-UA server — the standard protocol layer that lets supervisory systems talk to plant equipment — could silence the visibility operators depend on to catch process failures. That said, the OPC-UA server is off by default, and B&R's own architecture guidance places PPT30 devices behind network segmentation and firewalls; a reachable, unpatched unit represents a configuration failure as much as a software one.

The recurring lesson of ICS security advisories is that air-gap assumptions erode over time: maintenance VPNs, flat corporate-OT networks, and misconfigured firewalls keep putting "isolated" equipment within reach. Patch to 1.8.0, and if you genuinely need OPC-UA enabled, double-check what can actually reach port 4840.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →