CVE-2025-11044 Details
Description
An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on affected devices.
A denial-of-service vulnerability has been identified in the ANSL-Server component of B&R Automation Runtime. This issue affects versions prior to 6.5 and prior to R4.93. The vulnerability arises from a lack of proper throttling and resource allocation limits, allowing an unauthenticated attacker on the network to exploit a race condition. Successful exploitation can lead to permanent denial-of-service conditions on the affected devices.
Users are advised to update to B&R Automation Runtime versions 6.5 or later, or version R4.93 or later. Instructions for installing updates are available in the user manual. For customers unable to transition to a patched version, adjusting application configurations to longer cycle times may help mitigate the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 19, 2026CISA-ADP
Assessed Jan 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.br-automation.com/fileadmin/SA25P005-26597bd0.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| B&R Automation Runtime | < 6.5.0 (semver) < R4.93 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 19, 2026 | New CVE Received | [email protected] |
Volerion