ABB Advant Master Online Builder - Uncontrolled Search Path (DLL Search Order) Vulnerability
First seen Jul 15, 2026 · Updated Jul 15, 2026 · CVSS 4.4
ABB disclosed CVE-2025-13162, an uncontrolled search path (DLL hijacking) vulnerability affecting Online Builder (ONB) as included in Control Builder A and 800xA for Advant Master. A local attacker with prior system access could place a malicious DLL in an unrestricted application directory to achieve arbitrary code execution on the affected node.
Technical Analysis
CVE-2025-13162 (CWE-427: Uncontrolled Search Path Element) stems from Online Builder loading DLLs from an application directory with insufficient access restrictions, allowing an attacker who already has local or physical access to plant a malicious DLL that gets executed with the application's privileges. The flaw was reintroduced in 800xA for Advant Master 6.1.1-3 and 6.2.0-1 after being fixed in 6.1.1-2, due to an incorrect ONB version being bundled in release media; withdrawn versions 6.1.1-4 and 6.2.0-2 still present the vulnerable 6.1.1-3/6.2.0-1 builds via the System Installer/SCC. Exploitation requires local access (AV:L), high attack complexity, low privileges, and user interaction (CVSS 3.1: AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N, base score 4.4), and cannot be triggered remotely; it does not impact functional safety. This is a traditional OT/ICS engineering-workstation vulnerability with no direct relevance to AI agent frameworks, LLM tool use, or RAG pipelines, though organizations running AI-driven OT monitoring or automation agents on affected engineering workstations should ensure those agents do not execute with elevated privileges in the vulnerable directory context.
Affected Systems
ABB Control Builder A versions <=1.4/4; ABB 800xA for Advant Master versions <=6.0.3-1, <=6.1.1-1, 6.1.1-3, 6.1.1-4 (withdrawn), 6.2.0-1, 6.2.0-2 (withdrawn). Fixed in Control Builder A 1.4/5+, 800xA for Advant Master 6.1.1-5+ and 6.2.0-3+.
Indicators of Compromise
- Not applicable - this is a vendor-disclosed vulnerability advisory with no known active exploitation or associated indicators of compromise reported.
Remediation Steps
- 1
Apply vendor patches
Update Control Builder A to version 1.4/5 or later. Update 800xA for Advant Master to version 6.1.1-5 or later (from 6.0.3-1, 6.1.1-1 through 6.1.1-4) or version 6.2.0-3 or later (from 6.2.0-1/6.2.0-2).
- 2
Enforce access controls
Restrict system logon to authorized users only and enforce strong, regularly rotated passwords per ABB guidelines.
- 3
Restrict removable media
Disable or restrict ports for USB devices and other removable data carriers on systems accessible to regular users to prevent malicious DLL introduction.
- 4
Network segmentation
Isolate ICS/control system networks behind firewalls, minimize internet exposure, and use VPNs for any required remote access.
- 5
Contact vendor for interim workaround
If immediate patching is not feasible, contact ABB Support for a documented workaround while upgrade is scheduled.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.