Cross-Site Scripting Vulnerability in B&R Industrial Automation Product
CVE-2025-3448
5.1MEDIUM
What is CVE-2025-3448?
A Cross-Site Scripting (XSS) vulnerability exists in B&R Industrial Automation's Automation Runtime. This flaw allows attackers to inject malicious scripts into web pages viewed by users. The affected versions prior to 6.4 fail to adequately neutralize user input, creating potential security risks for organizations using these automation systems. Mitigation strategies include implementing stringent input validation and sanitization processes.
Affected Version(s)
Automation Runtime 6.0 < 6.4