XZ Utils vulnerability impacting B&R Products
Plan PatchCVSS 7.5ICS-CERT ICSA-26-181-05Jun 10, 2026
Manufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A vulnerability in XZ Utils affects multiple B&R industrial terminals. An attacker with network access could send a malicious packet that causes the terminal to stop responding or corrupts memory data. The vulnerability requires no authentication or user interaction. B&R has released firmware updates for all affected models.
What this means
What could happen
An attacker could crash B&R industrial terminals or corrupt memory, disrupting manufacturing processes and potentially losing production data. The vulnerability requires network access but no authentication or user interaction.
Who's at risk
Manufacturing facilities using B&R industrial terminals (PPC3100, C50, C80, FT50, MT50, T30, T80, T50 models) for process control and automation. These human-machine interface and control terminals are critical to production operations.
How it could be exploited
An attacker with network access to an affected B&R terminal sends a specially crafted packet that triggers the XZ Utils vulnerability. This causes the terminal to stop responding (denial of service) or corrupts memory data stored on the device.
Prerequisites
- Network connectivity to the affected B&R terminal on its listening port
- Terminal must be running a vulnerable firmware version (below 1.8.0 or 1.8.1 depending on model)
remotely exploitableno authentication requiredlow complexityaffects availability of critical control equipment
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
PPC3100 <1.8.1<1.8.11.8.1
C50 <1.8.0<1.8.01.8.0
C80 <1.8.0<1.8.01.8.0
FT50 <1.8.1<1.8.11.8.1
MT50 <1.8.1<1.8.11.8.1
T30 <1.8.0<1.8.01.8.0
T80 <1.8.0<1.8.01.8.0
T50 <1.8.1<1.8.11.8.1
Remediation & Mitigation
0/5
Do now
0/1WORKAROUNDRestrict network access to affected terminals using firewall rules to allow only trusted engineering workstations and control systems
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
HOTFIXUpdate PPC3100 terminals to firmware version 1.8.1 or later
HOTFIXUpdate C50 and C80 terminals to firmware version 1.8.0 or later
HOTFIXUpdate FT50, MT50, and T50 terminals to firmware version 1.8.1 or later
HOTFIXUpdate T30 and T80 terminals to firmware version 1.8.0 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f2d72579-18ee-46f9-8624-72d7b2ae7386Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.