HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Uncontrolled Search Path Vulnerability (CVE‑2025‑13162) in ABB Advant Master Online Builder Risks Unauthorized Code Execution

ABB disclosed CVE‑2025‑13162 in its Advant Master Online Builder, a low‑to‑medium severity flaw that allows loading of DLLs from untrusted directories. The issue can lead to unauthorized code execution if an attacker gains local access, underscoring the need for robust control‑mapping and continuous compliance evidence.

LiveThreat™ Intelligence · 📅 July 14, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Uncontrolled Search Path Vulnerability (CVE‑2025‑13162) in ABB Advant Master Online Builder

What It Is — ABB disclosed an “uncontrolled search path element” flaw in its Advant Master Online Builder (Control Builder A ≤ 1.4/4 and 800xA ≤ 6.2.0‑1). The defect lets the application load DLLs from directories that are not trusted, opening a path for DLL‑hijacking‑style code execution.

Exploitability — CVSS v3 score 4.4 (Low‑to‑Medium). No public exploit or malware‑as‑a‑service has been observed, but an attacker who already has local access could trigger the flaw.

Affected Products — ABB Advant Master Online Builder (Control Builder A ≤ 1.4/4; 800xA for Advant Master ≤ 6.0.3‑1, ≤ 6.1.1‑1, 6.1.1‑3, ≤ 6.2.0‑1).

Why It Matters for Compliance & Audit Readiness

  • The vulnerability highlights a control‑mapping gap: the software’s library‑loading behavior is not documented or monitored against your security policies.
  • Continuous evidence of patch status and configuration baselines is a core SOC 2 control (CC6.1 – Change Management). Demonstrating that you track and remediate such flaws satisfies auditors and reduces vendor‑risk exposure.
  • Enterprise buyers increasingly demand proof that critical‑infrastructure vendors maintain a defensible audit trail for configuration changes and vulnerability remediation.

Recommended Actions

  • Apply the ABB‑provided patch immediately.
  • Update your configuration‑management database (CMDB) to record the corrected search‑path settings.
  • Map the DLL‑search‑path control to SOC 2 CC6.1 and capture the patch‑deployment evidence in a continuous‑compliance repository.
  • Conduct a post‑remediation validation scan to confirm the vulnerability is closed.

Source: CISA Advisory – ICSA‑26‑195‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →