news.mlab.sh
Back to the feed
threat-intel

ABB Advant Master Online Builder

High
Summary

ABB has identified and addressed a vulnerability in its Advant Master Online Builder software, where an incorrect version of the Online Builder could lead to unauthorized DLL loading and potential code execution. The vulnerability stems from a lack of restrictions on the application directory, allowing attackers with physical access to install malicious DLLs. ABB has released updates to resolve the issue, and CISA recommends implementing defensive measures to minimize exploitation risk, including network segmentation and secure remote access practices.

ABB became aware of a vulnerability in its Advant Master Online Builder software, where an incorrect version of Online Builder (ONB) could be included in the media, leading to unauthorized DLL loading and potential code execution. The vulnerability is caused by a lack of restrictions on the application directory, allowing an attacker who obtains physical access to the system to insert and run arbitrary code.

**What happened**

The vulnerability allows an attacker to place malicious DLLs in an unrestricted application directory, resulting in unauthorized code execution and compromising system integrity. The issue was identified through ABB’s internal security assessment and verification processes and has since been remediated.

**Technical details**

  • **Affected Products:** ABB Advant Master Online Builder, ABB Control Builder A <=1.4/4, ABB 800xA for Advant Master <=6.0.3-1, ABB 800xA for Advant Master <=6.1.1-1, ABB 800xA for Advant Master 6.1.1-3, ABB 800xA for Advant Master 6.2.0-1
  • **Vulnerability Type:** DLL Injection
  • **CWE Identifier:** CWE-427 Uncontrolled Search Path Element
  • **CVSS Score:** Not available
  • **Exploitation Status:** Not exploited (as of advisory release)

**Impact**

  • **Scope:** An attacker who successfully exploits this vulnerability could insert and run arbitrary code in an affected node.
  • **Risk:** High – due to the potential for remote code execution and system compromise.

**What to do**

  • **Vendor Fix:** ABB has released updates to address the vulnerability. Specific versions fixed include: ABB 800xA for Advant Master <=6.0.3-1, ABB 800xA for Advant Master <=6.1.1-1, ABB 800xA for Advant Master 6.1.1-3, ABB 800xA for Advant Master 6.2.0-1.
  • **Mitigation:**
  • Upgrade to the latest version of Advant Master Online Builder.
  • Restrict access to the application directory.
  • Implement secure remote access practices (e.g., VPNs).
  • Segment control system networks from business networks.

**Why it matters** This vulnerability poses a significant risk to critical infrastructure systems relying on ABB’s Advant Master controllers. Successful exploitation could lead to complete system compromise and disruption of industrial operations. The advisory highlights the importance of proactive security measures and timely patching to minimize the attack surface.

Read the full article at CISA Advisories