CVE-2025-11043 PUBLISHED

Improper Server Certificate Validation in Automation Studio

Assigner: ABB
Reserved: 26.09.2025 Published: 19.01.2026 Updated: 20.01.2026

An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.1

Product Status

Vendor B&R Industrial Automation GmbH
Product B&R Automation Studio
Versions Default: unaffected
  • Version 4 is affected
  • affected from 6 to 6.5 (excl.)

References

Problem Types

  • CWE-295 Improper Certificate Validation CWE