PatchSiren cyber security CVE debrief
CVE-2025-13162 ABB CVE debrief
CVE-2025-13162 is an Uncontrolled Search Path Element vulnerability affecting ABB Control Builder A and ABB 800xA for Advant Master. The issue exists in Control Builder A versions up to 1.4/4 and 800xA for Advant Master versions up to 6.0.3-1, 6.1.1-1, 6.1.1-3, and 6.2.0-1. This vulnerability has a CVSS score of 4.1, indicating a medium severity level. The CVE was published on June 23, 2026, and last modified on June 25, 2026. ABB has provided a reference document for further information.
- Vendor
- ABB
- Product
- Control Builder A
- CVSS
- MEDIUM 4.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-23
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-23
- Advisory updated
- 2026-06-25
Who should care
Organizations using ABB Control Builder A and ABB 800xA for Advant Master should prioritize patching this vulnerability to prevent potential local attacks. The vulnerability requires a local attack vector and has a high attack complexity, but successful exploitation could lead to high impact on integrity. Security teams and administrators responsible for these systems should take immediate action.
Technical summary
The Uncontrolled Search Path Element vulnerability in ABB Control Builder A and ABB 800xA for Advant Master allows a local attacker with low privileges to potentially exploit the vulnerability, leading to high impact on integrity. The vulnerability is triggered by an uncontrolled search path element. ABB has released a reference document (https://search.abb.com/library/Download.aspx?DocumentID=7PAA020047&LanguageCode=en&DocumentPartId=&Action=Launch) that provides further details and mitigation strategies.
Defensive priority
Apply patches or mitigations as recommended by ABB to prevent exploitation. Review and update system configurations to ensure they align with security best practices.
Recommended defensive actions
- Apply patches or mitigations as recommended by ABB.
- Review and update system configurations to ensure they align with security best practices.
- Monitor systems for suspicious activity.
- Implement compensating controls to reduce the attack surface.
- Conduct regular vulnerability assessments and penetration testing.
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, its impact, and potential mitigations. ABB has also provided a reference document for further information. The vulnerability has a medium CVSS score of 4.1, indicating a moderate level of severity.
Official resources
-
CVE-2025-13162 CVE record
CVE.org
-
CVE-2025-13162 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
This article is AI-assisted and based on the supplied source corpus.