PT-2025-41144 · B&R Industrial Automation · B&R Automation Runtime

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-3448

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions B&R Industrial Automation Automation Runtime versions prior to 6.4
Description An issue exists in B&R Industrial Automation Automation Runtime that allows for improper neutralization of input during web page generation, potentially leading to Cross-site Scripting (XSS). This could allow an attacker to inject malicious scripts into web pages viewed by users.
Recommendations Update Automation Runtime to version 6.4 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-3448

Affected Products

B&R Automation Runtime