CVE-2023-5778: Missing Length Check
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.
This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
Affected Software
Event History
Frequently Asked Questions
Which controller versions are affected?
Affected ABB Freelance Controller DCP, AC700, AC800, and AC900 releases include 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1, as well as versions through those releases.
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the expected security impact?
The supplied severity data rates the issue high at 7.5 and indicates an availability impact without confidentiality or integrity impact.