CVE-2025-7064: Freelance Security Lock – Access to Windows OS
Authentication bypass by primary weakness vulnerability in ABB Freelance.
This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable the Freelance Security Lock feature to restrict access to the Windows operating system for affected Freelance installations (this issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024).
ABB Freelance Freelance Security Lock – Access to Windows OS = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7064?
CVE-2025-7064 has a medium severity score of 5.6.
What systems are affected by CVE-2025-7064?
CVE-2025-7064 affects ABB Freelance versions from 2013 to 2024, including specific service packs.
What is the impact of CVE-2025-7064?
CVE-2025-7064 allows for authentication bypass, which can lead to unauthorized access to the Windows operating system.
How do I fix CVE-2025-7064?
To mitigate CVE-2025-7064, users should apply the latest security updates provided by ABB for affected Freelance versions.
Is user interaction required to exploit CVE-2025-7064?
No, user interaction is not required to exploit CVE-2025-7064 as it has a UI:N rating.