8.9
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Description
An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on affected devices.
AI Analysis
Allocation of Resources Without Limits or Throttling vulnerability in ANSL-Server component, resulting in permanent denial-of-service (DoS) conditions
Basic Information
ID
CVE-2025-11044
Source
ABB
Published
Jan 19, 2026 at 15:57
Affected Product
Vendor
B&R Industrial Automation GmbH
Product
Automation Runtime
Version
4
Affected Versions
B&R Industrial Automation GmbH Automation Runtime 4
B&R Industrial Automation GmbH Automation Runtime 6
B&R Industrial Automation GmbH Automation Runtime 6
CWE Classification
AI Assessment
AI Score
8.9 / 10
AI Severity
High
Vendor
B&R Industrial Automation GmbH
Product
Automation Runtime
Version
prior to 6.5, prior to R4.93