B&R patches XZ Utils flaw in eight controller lines
An open-source compression bug inside controllers turns dependency inventory into a production-line availability problem that cannot wait for audit season.
TL;DR
CISA republished ABB PSIRT SA26P009 for CVE-2025-31115, a high-severity race condition in XZ Utils' multithreaded decoder affecting B&R PPC3100, C50, C80, FT50, MT50, T30, T80 and T50 controllers. Critical manufacturing operators, including state, municipal and defense suppliers running those systems, should identify installed Terminal OS versions and apply B&R's fixes. B&R reported no exploitation information at original issuance, but the advisory leaves the public-disclosure timeline thin.
CISA's advisory is short because the operating instruction is short: find the B&R controller, check the Terminal OS version, install the model-specific update. PPC3100, FT50, MT50 and T50 are fixed at 1.8.1. C50, C80, T30 and T80 are fixed at 1.8.0. The vulnerable versions use XZ Utils' multithreaded .xz decoder in liblzma, where invalid input can trigger a crash, heap use after free, or writes based on a null pointer offset. B&R assigns CVSS 7.5 high and says remote exploitation is possible for an attacker with network access to the affected node.
That makes CISA's standard industrial control system network guidance directly relevant. For production controllers in critical manufacturing, no direct internet connection and segmentation from business networks are availability controls, not decoration. State CISOs, municipal IT teams, and defense-industrial-base suppliers with B&R gear should treat the sequence as asset discovery first, patch planning second, outage risk third.
The less tidy part is provenance. CISA says this is a verbatim republication of ABB PSIRT SA26P009, provided as-is, and the revision history shows the vendor's initial version on June 10 and CISA's republication on June 30. B&R says the vulnerability had been publicly disclosed and that it had no information indicating exploitation when the advisory was originally issued. The advisory does not give the public disclosure date, so incident responders get the comforting answer only in broad shape: no known exploitation reported to B&R, but a public bug existed before this appeared in the CISA ICS feed.
Compliance teams should resist filing this under a B&R-only firmware defect and moving on. The flaw is in XZ Utils, a general-purpose compression library used by software far outside industrial automation. CISA's March 2024 alert on malicious code in XZ Utils versions 5.6.0 and 5.6.1 made the same dependency point under worse facts, with the agency telling users to downgrade, hunt, and report findings (https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094). This advisory is cleaner: fixed controller versions are named. The hard part is still proving where the library is hiding.
Published ·Deep Fathom