Uncontrolled Search Path Vulnerability (CVE‑2025‑13162) in ABB Advant Master Online Builder
What It Is — ABB disclosed an “uncontrolled search path element” flaw in its Advant Master Online Builder (Control Builder A ≤ 1.4/4 and 800xA ≤ 6.2.0‑1). The defect lets the application load DLLs from directories that are not trusted, opening a path for DLL‑hijacking‑style code execution.
Exploitability — CVSS v3 score 4.4 (Low‑to‑Medium). No public exploit or malware‑as‑a‑service has been observed, but an attacker who already has local access could trigger the flaw.
Affected Products — ABB Advant Master Online Builder (Control Builder A ≤ 1.4/4; 800xA for Advant Master ≤ 6.0.3‑1, ≤ 6.1.1‑1, 6.1.1‑3, ≤ 6.2.0‑1).
Why It Matters for Compliance & Audit Readiness
- The vulnerability highlights a control‑mapping gap: the software’s library‑loading behavior is not documented or monitored against your security policies.
- Continuous evidence of patch status and configuration baselines is a core SOC 2 control (CC6.1 – Change Management). Demonstrating that you track and remediate such flaws satisfies auditors and reduces vendor‑risk exposure.
- Enterprise buyers increasingly demand proof that critical‑infrastructure vendors maintain a defensible audit trail for configuration changes and vulnerability remediation.
Recommended Actions
- Apply the ABB‑provided patch immediately.
- Update your configuration‑management database (CMDB) to record the corrected search‑path settings.
- Map the DLL‑search‑path control to SOC 2 CC6.1 and capture the patch‑deployment evidence in a continuous‑compliance repository.
- Conduct a post‑remediation validation scan to confirm the vulnerability is closed.
Source: CISA Advisory – ICSA‑26‑195‑01