www.cisa.gov 6/4/2026, 4:11:09 PM · external

CVE-2025-11482 flaw disables B&R OPC UA server, update urged

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

THE ICS Advisory ICSA-26-155-03, released on June 4, 2026, informs about a vulnerability in the B&R PPT30 Operating System that affects versions prior to 1.8.0, specifically identified as CVE-2025-11482. This vulnerability could allow unauthenticated attackers to make the OPC-UA server inaccessible, impacting users' ability to connect. The advisory highlights that the CVSS score is 7.5, indicating high severity.

B&R recommends users upgrade to version 1.8.0 or later, where necessary configurations and firewall settings are advised to mitigate risks. Organizations are urged to employ recommended security practices to protect against exploitation.

View full article

Article by CyberSIXT