Status: UPDATED | Advisory ID: CVE-2023-5778
| CVE | CVE-2023-5778 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-18 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900 |
| Classified as | CWE-130 (Improper Handling of Length Parameter Inconsistency) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| ABB | Freelance Controller DCP | ||
| ABB | Freelance Controller AC700 | ||
| ABB | Freelance Controller AC800 | ||
| ABB | Freelance Controller AC900 |
| Subsystems | General OT |
| Sectors | Multiple |
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.
This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1. (NVD)
Monitor ABB's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2023-5778 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2023-5778 |