Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Br-automation
Br-automation automation Runtime |
|
| Vendors & Products |
Br-automation
Br-automation automation Runtime |
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a malicious link. The user would need to click on this link, after which the resulting CSV file addi-tionally needs to be manually opened. | |
| Title | CSV Formula Injection Vulnerability | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2025-10-14T15:31:36.665Z
Reserved: 2025-10-08T13:55:00.714Z
Link: CVE-2025-11498
Updated: 2025-10-14T15:31:33.568Z
Status : Deferred
Published: 2025-10-14T13:15:36.767
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11498
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:42:51Z