Executive Summary
In June 2026, ABB identified a vulnerability (CVE-2025-13162) in its Advant Master Online Builder software, affecting Control Builder A versions up to 1.4/4 and 800xA for Advant Master versions up to 6.2.0-1. The flaw, an uncontrolled search path element, could allow unauthorized code execution if exploited by an attacker with local access. ABB promptly released updates to remediate the issue and advised customers to upgrade to the latest versions to maintain system integrity.
This incident underscores the critical importance of timely software updates and vigilant access control in industrial control systems. As cyber threats targeting operational technology environments continue to evolve, organizations must prioritize proactive vulnerability management to safeguard critical infrastructure.
Why This Matters Now
The ABB Advant Master Online Builder vulnerability highlights the ongoing risks in industrial control systems, emphasizing the need for immediate software updates and stringent access controls to protect critical infrastructure from emerging cyber threats.
Attack Path Analysis
An attacker with local access exploited a DLL search path vulnerability in ABB Advant Master Online Builder to execute unauthorized code, escalating privileges to gain administrative control. They moved laterally within the network to access critical systems, established command and control channels to maintain persistence, exfiltrated sensitive data, and ultimately disrupted operations by modifying system configurations.
Kill Chain Progression
Initial Compromise
Description
An attacker with local access exploited the uncontrolled DLL search path vulnerability (CVE-2025-13162) in ABB Advant Master Online Builder to execute unauthorized code.
Related CVEs
CVE-2025-13162
CVSS 4.4The application improperly handles the search path for loading DLLs, potentially allowing unauthorized libraries from untrusted directories. An attacker who obtains the necessary access could exploit the vulnerability, leading to unauthorized code execution and compromising system integrity.
Affected Products:
ABB Control Builder A – <=1.4/4
ABB 800xA for Advant Master – <=6.0.3-1, <=6.1.1-1, 6.1.1-3, 6.2.0-1
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Hijack Execution Flow: DLL
Hijack Execution Flow: Path Interception by Search Order Hijacking
Hijack Execution Flow: Path Interception by PATH Environment Variable
Hijack Execution Flow: Path Interception by Unquoted Path
Hijack Execution Flow: Dynamic Linker Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Software, Firmware, and Information Integrity
Control ID: SI-7
PCI DSS 4.0 – Ensure that all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: Pillar 3: Devices
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical infrastructure control systems using ABB Advant Master face DLL hijacking vulnerabilities enabling unauthorized code execution in power generation facilities.
Oil/Energy/Solar/Greentech
Energy sector automation systems vulnerable to supply chain attacks through compromised control builder software allowing attackers to manipulate critical operations.
Industrial Automation
Manufacturing control systems exposed to privilege escalation attacks via uncontrolled search path elements in widely-deployed ABB industrial control platforms.
Chemicals
Chemical processing facilities risk safety system compromise through local access exploitation of ABB control infrastructure enabling potential operational disruption.
Sources
- ABB Advant Master Online Builderhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01Verified
- ABB Advant Master Online Builder DLL Vulnerabilityhttps://library.e.abb.com/public/f34626b2c8b9451bb995b3e6c33d2ade/7PAA020047_C_en%20Advant%20Master%20Online%20Builder%20DLL%20vulnerability.pdfVerified
- NVD - CVE-2025-13162https://nvd.nist.gov/vuln/detail/CVE-2025-13162Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware routing.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute unauthorized code may be limited by enforcing strict workload isolation and identity-aware routing.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may be constrained by limiting access to critical systems through strict segmentation.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network could be limited by enforcing east-west traffic controls.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels may be constrained by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could be limited by enforcing strict egress policies.
The attacker's ability to disrupt operations may be constrained by limiting access to critical system configurations.
Impact at a Glance
Affected Business Functions
- Control System Configuration
- Industrial Process Management
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy East-West Traffic Security controls to monitor and prevent unauthorized internal communications.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Regularly update and patch systems to mitigate known vulnerabilities like CVE-2025-13162.



