IM
IronMonkey Threat Research
‹ Back to ICS Advisories

ABB Automation Builder - Deserialization of untrusted data

HIGH
CVSS 7.8
Date 2026-09-28T00:30:00+00:00
Source abb-psirt
Published by ABB PSIRT

// Description

ABB is aware of vulnerabilities in the products versions listed as affected in the advisory. Automation Builder could execute arbitrary code by crafting the project file or project archive file.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-41700 7.8 high
CVE-2025-41700. A vulnerability has been discovered in the print engine of Automation Builder. If an Automation Builder project file or archive file was crafted in a specific way, the Automation Builder could execute arbitrary code when a user opens these files and configures the print/printer options or prints the project or parts of it. This arbitrary code would be executed in the context of the user who was tricked into opening the project.

// Affected Products (10)

Vendor Product Asset Type Purdue Level Firmware
CODESYS, GmbH Unknown engineering_workstation
L3
--
CODESYS, GmbH Unknown engineering_workstation
L3
--
CODESYS, GmbH Unknown engineering_workstation
L3
--
CODESYS Unknown engineering_workstation
L3
--
CODESYS, GmbH Unknown plc
L1
--
CODESYS, GmbH Unknown engineering_workstation
L3
--
CODESYS Unknown engineering_workstation
L3
3.5.21.20
CODESYS Unknown engineering_workstation
L3
--
CODESYS Unknown engineering_workstation
L3
--
CODESYS GmbH Unknown engineering_workstation
L3
3.3.5.0

// Remediations (2)

Workaround: Workarounds are specific measures that a user can take to help block an attack, for example, tempora
Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors. When a workaround reduces functionality, this is identified below as “Impact of work-around”. The vulnerability can be closed by enabling local access only. See chapter “Recommended immediate actions” for details.
Patch: The problem is corrected in the following product version: - Automation Builder 2.9.1 ABB recommend
The problem is corrected in the following product version: - Automation Builder 2.9.1 ABB recommends that customers apply the update at earliest convenience. Automation Builder 2.9.1 is available for download from the related download site.

// References