PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-13162 ABB CVE debrief

CVE-2025-13162 is an Uncontrolled Search Path Element vulnerability affecting ABB Control Builder A and ABB 800xA for Advant Master. The issue exists in Control Builder A versions up to 1.4/4 and 800xA for Advant Master versions up to 6.0.3-1, 6.1.1-1, 6.1.1-3, and 6.2.0-1. This vulnerability has a CVSS score of 4.1, indicating a medium severity level. The CVE was published on June 23, 2026, and last modified on June 25, 2026. ABB has provided a reference document for further information.

Vendor
ABB
Product
Control Builder A
CVSS
MEDIUM 4.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-23
Original CVE updated
2026-06-25
Advisory published
2026-06-23
Advisory updated
2026-06-25

Who should care

Organizations using ABB Control Builder A and ABB 800xA for Advant Master should prioritize patching this vulnerability to prevent potential local attacks. The vulnerability requires a local attack vector and has a high attack complexity, but successful exploitation could lead to high impact on integrity. Security teams and administrators responsible for these systems should take immediate action.

Technical summary

The Uncontrolled Search Path Element vulnerability in ABB Control Builder A and ABB 800xA for Advant Master allows a local attacker with low privileges to potentially exploit the vulnerability, leading to high impact on integrity. The vulnerability is triggered by an uncontrolled search path element. ABB has released a reference document (https://search.abb.com/library/Download.aspx?DocumentID=7PAA020047&LanguageCode=en&DocumentPartId=&Action=Launch) that provides further details and mitigation strategies.

Defensive priority

Apply patches or mitigations as recommended by ABB to prevent exploitation. Review and update system configurations to ensure they align with security best practices.

Recommended defensive actions

  • Apply patches or mitigations as recommended by ABB.
  • Review and update system configurations to ensure they align with security best practices.
  • Monitor systems for suspicious activity.
  • Implement compensating controls to reduce the attack surface.
  • Conduct regular vulnerability assessments and penetration testing.

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, its impact, and potential mitigations. ABB has also provided a reference document for further information. The vulnerability has a medium CVSS score of 4.1, indicating a moderate level of severity.

Official resources

This article is AI-assisted and based on the supplied source corpus.