Executive brief
ABB Control Builder A and 800xA for Advant Master, which are used to configure and manage industrial control systems, are vulnerable to a security flaw that could allow an attacker to execute unauthorized code. An attacker with local access to the system could trick a legitimate user into running a malicious file, potentially compromising the integrity of the industrial control environment. This could lead to unauthorized changes in system configurations or operational disruptions.
Technical details
An uncontrolled search path element vulnerability (CWE-427) exists in ABB Control Builder A and 800xA for Advant Master. The vulnerability stems from the application searching for critical resources or libraries in directories that may be writable by a local user. An attacker with low privileges could place a malicious executable or library (such as a DLL) in the search path. Exploitation requires user interaction, typically involving a legitimate user executing the application while the malicious file is present in a high-priority search directory. Successful exploitation allows the attacker to execute code with the privileges of the application, potentially leading to unauthorized system modifications.
Affected products
- ABB Control Builder A through 1.4/4
- ABB 800xA for Advant Master through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1
Timeline
- 2026-06-23: advisory: Initial advisory published by ABB