ABB Advant Master Online Builder
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions. The following versions of ABB Advant Master Online Builder are affected: Control Builder A <=1.4/4 (CVE-2025-13162) 800xA for Advant Master <=6.0.3-1, <=6.1.1-1, 6.1.1-3, 6.2.0-1 (CVE-2025-13162, CVE-2025-13162, CVE-2025-13162, CVE-2025-13162) CVSS Vendor Equipment Vulnerabilities v3 4.4 ABB ABB Advant Master Online Builder Uncontrolled Search Path Element Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-13162 The application improperly handles the search path for loading DLL´s, potentially allowing unauthorized libraries from untrusted directories. An attacker who obtains the necessary access could exploit the vulnerability leading to unauthorized code execution and compromising system integrity. View CVE Details Affected Products ABB Advant Master Online Builder Vendor: ABB Product Version: ABB Control Builder A <=1.4/4, ABB 800xA for Advant Master <=6.0.3-1, ABB 800xA for Advant Master <=6.1.1-1, ABB 800xA for Advant Master 6.1.1-3, ABB 800xA for Advant Master 6.2.0-1 Product Status: known_affected Remediations Vendor fix ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). V
CSIRTS triage
- What
- An incorrect version of Online Builder was included in the media.
- Who is affected
- Users of affected versions of ABB Advant Master Online Builder.
- Urgency
- Remediation is critical due to the potential impact on system integrity.
- Action
- Update to the correct version of Online Builder.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Advant Master Online Builder
Get an email when a new Advant Master Online Builder advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-131620.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-13162 | coverage & exploitation status | NVD · CVE.org |
More from CISA Cybersecurity Advisories
- criticalSchneider Electric IGSS2026-07-30
- criticalRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- unknownMitsubishi Electric CC-Link IE TSN Communication Protocol2026-07-30
- criticalOpen Source Software: Security Principles and Practices2026-07-30