mediumOther

ABB Advant Master Online Builder - Uncontrolled Search Path (DLL Search Order) Vulnerability

First seen Jul 15, 2026 · Updated Jul 15, 2026 · CVSS 4.4

ICSSCADADLL-hijackinglocal-privilege-escalationABBCWE-427critical-infrastructure

ABB disclosed CVE-2025-13162, an uncontrolled search path (DLL hijacking) vulnerability affecting Online Builder (ONB) as included in Control Builder A and 800xA for Advant Master. A local attacker with prior system access could place a malicious DLL in an unrestricted application directory to achieve arbitrary code execution on the affected node.

Technical Analysis

CVE-2025-13162 (CWE-427: Uncontrolled Search Path Element) stems from Online Builder loading DLLs from an application directory with insufficient access restrictions, allowing an attacker who already has local or physical access to plant a malicious DLL that gets executed with the application's privileges. The flaw was reintroduced in 800xA for Advant Master 6.1.1-3 and 6.2.0-1 after being fixed in 6.1.1-2, due to an incorrect ONB version being bundled in release media; withdrawn versions 6.1.1-4 and 6.2.0-2 still present the vulnerable 6.1.1-3/6.2.0-1 builds via the System Installer/SCC. Exploitation requires local access (AV:L), high attack complexity, low privileges, and user interaction (CVSS 3.1: AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N, base score 4.4), and cannot be triggered remotely; it does not impact functional safety. This is a traditional OT/ICS engineering-workstation vulnerability with no direct relevance to AI agent frameworks, LLM tool use, or RAG pipelines, though organizations running AI-driven OT monitoring or automation agents on affected engineering workstations should ensure those agents do not execute with elevated privileges in the vulnerable directory context.

Affected Systems

ABB Control Builder A versions <=1.4/4; ABB 800xA for Advant Master versions <=6.0.3-1, <=6.1.1-1, 6.1.1-3, 6.1.1-4 (withdrawn), 6.2.0-1, 6.2.0-2 (withdrawn). Fixed in Control Builder A 1.4/5+, 800xA for Advant Master 6.1.1-5+ and 6.2.0-3+.

Indicators of Compromise

  • Not applicable - this is a vendor-disclosed vulnerability advisory with no known active exploitation or associated indicators of compromise reported.

Remediation Steps

  1. 1

    Apply vendor patches

    Update Control Builder A to version 1.4/5 or later. Update 800xA for Advant Master to version 6.1.1-5 or later (from 6.0.3-1, 6.1.1-1 through 6.1.1-4) or version 6.2.0-3 or later (from 6.2.0-1/6.2.0-2).

  2. 2

    Enforce access controls

    Restrict system logon to authorized users only and enforce strong, regularly rotated passwords per ABB guidelines.

  3. 3

    Restrict removable media

    Disable or restrict ports for USB devices and other removable data carriers on systems accessible to regular users to prevent malicious DLL introduction.

  4. 4

    Network segmentation

    Isolate ICS/control system networks behind firewalls, minimize internet exposure, and use VPNs for any required remote access.

  5. 5

    Contact vendor for interim workaround

    If immediate patching is not feasible, contact ABB Support for a documented workaround while upgrade is scheduled.

CVE / Advisory IDs

CVE-2025-13162

Industries Most Exposed

Critical ManufacturingIndustrial Control SystemsEnergyUtilities

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.