CVE-2023-5778
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.
This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ABB | Freelance Controller DCP | 0 <= 2013 | affected |
| ABB | Freelance Controller DCP | 2013 SP1 | affected |
| ABB | Freelance Controller DCP | 2016 | affected |
| ABB | Freelance Controller DCP | 2016 SP1 | affected |
| ABB | Freelance Controller DCP | 2019 | affected |
| ABB | Freelance Controller DCP | 2019 SP1 | affected |
| ABB | Freelance Controller DCP | 2019 SP1 FP1 | unaffected |
| ABB | Freelance Controller DCP | 2024 | unaffected |
| ABB | Freelance Controller AC700 | 0 <= 2013 | affected |
| ABB | Freelance Controller AC700 | 2013 SP1 | affected |
| ABB | Freelance Controller AC700 | 2016 | affected |
| ABB | Freelance Controller AC700 | 2016 SP1 | affected |
| ABB | Freelance Controller AC700 | 2019 | affected |
| ABB | Freelance Controller AC700 | 2019 SP1 | affected |
| ABB | Freelance Controller AC700 | 2019 SP1 FP1 | unaffected |
| ABB | Freelance Controller AC700 | 2024 | unaffected |
| ABB | Freelance Controller AC800 | 0 <= 2013 | affected |
| ABB | Freelance Controller AC800 | 2013 SP1 | affected |
| ABB | Freelance Controller AC800 | 2016 | affected |
| ABB | Freelance Controller AC800 | 2016 SP1 | affected |
| ABB | Freelance Controller AC800 | 2019 | affected |
| ABB | Freelance Controller AC800 | 2019 SP1 | affected |
| ABB | Freelance Controller AC800 | 2019 SP1 FP1 | unaffected |
| ABB | Freelance Controller AC800 | 2024 | unaffected |
| ABB | Freelance Controller AC900 | 0 <= 2013 | affected |
| ABB | Freelance Controller AC900 | 2013 SP1 | affected |
| ABB | Freelance Controller AC900 | 2016 | affected |
| ABB | Freelance Controller AC900 | 2016 SP1 | affected |
| ABB | Freelance Controller AC900 | 2019 | affected |
| ABB | Freelance Controller AC900 | 2019 SP1 | affected |
| ABB | Freelance Controller AC900 | 2019 SP1 FP1 | unaffected |
| ABB | Freelance Controller AC900 | 2024 | unaffected |
Weaknesses
- CWE-130: CWE-130 Improper handling of length parameter inconsistency
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.