← All Advisories

CVE-2023-5778

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2023-5778

Key Details

CVECVE-2023-5778
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-18
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900
Classified asCWE-130 (Improper Handling of Length Parameter Inconsistency)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
ABBFreelance Controller DCP
ABBFreelance Controller AC700
ABBFreelance Controller AC800
ABBFreelance Controller AC900
SubsystemsGeneral OT
SectorsMultiple

What to Know

Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.

This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1. (NVD)

What to Do

Monitor ABB's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2023-5778
CVEhttps://www.cve.org/CVERecord?id=CVE-2023-5778