The vendor explicitly identifies these products as affected by this CVE.
- All ABB Automation Builder <= 2.8.0
- Summary
- Automation Builder stores all user management information in the project file. Despite fully encrypted password data, an attacker could try to modify parts of the Automation Builder project file by specially crafted contents so that the user management will be overruled.
- Remediation
- Immediate workarounds to close the vulnerability: • CVE-2025-3394: In the project settings, set “Security” to “Integrity check” ABB recommends that customers apply the workarounds at earliest convenience. With the next Automation Builder version 2.8.1, the default for “Security” will be set to “Integrity check”. The release of Automation Builder version 2.8.1 is scheduled for July 2025.
