ABB patches CVE-2025-13162 in Advant Master Online Builder
A 4.4 CVSS score is the wrong comfort metric when plant-floor local access already means the perimeter failed.
TL;DR
CISA relayed ABB’s patch guidance for CVE-2025-13162, a CVSS 4.4 uncontrolled DLL search-path flaw in Advant Master Online Builder that can permit local code execution. The remediation path covers Control Builder A 1.4/4 and earlier and 800xA for Advant Master 6.0.3-1, 6.1.1-1 through 6.1.1-4, and 6.2.0-1. Primes, contractors and MSPs supporting critical manufacturing sites should update to Control Builder A 1.4/5, 800xA 6.1.1-5, or 6.2.0-3. ABB also withdrew builds after reintroducing or mis-presenting the vulnerable Online Builder.
CISA's advisory is routine only if the reader treats CVSS 4.4 as the story. ABB says CVE-2025-13162 lets an attacker with physical access to an affected system node place malicious DLLs in an unrestricted application directory and execute code. The fix is to move Control Builder A to 1.4/5 or later, 800xA for Advant Master 6.0.3-1 and 6.1.1 branch customers to 6.1.1-5 or later, and 6.2.0 customers to 6.2.0-3 or later. ABB says 6.1.1-2 did not contain the vulnerable Online Builder, but the remediation path still steers that branch to 6.1.1-5 because 6.1.1-3 reintroduced the older component and 6.1.1-4 displayed the withdrawn 6.1.1-3 through the installer. The practitioner issue is version truth: inventory the actual media and installer-presented version before assuming the installed branch is clean. CISA also repeats the standard OT advice: isolate control systems, keep remote access behind updated VPNs, restrict removable media, and assess operational impact before deploying defenses.
Published ·Deep Fathom