Description

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves
the reported vulnerabilities in the product versions under maintenance.
An attacker who successfully exploited one or more of these vulnerabilities could cause the product to
stop or make the product inaccessible.



Stack-based Buffer Overflow vulnerability in ABB Freelance controllers AC 700F (conroller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:

 Freelance controllers AC 700F: 

from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019 , through Freelance 2019 SP1, through Freelance 2019 SP1 FP1; 




Freelance controllers AC 900F: 

through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

Published: 2023-08-07
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerabilities, they can help block known attack vectors. CVE-2023-0426: Stack Overflow We recommend disabling the webserver when not needed. The webserver is disabled by default from Freelance 2019 SP1 FP1 on (see Release Notes 2PAA124716-112).

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-12483 ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible. Stack-based Buffer Overflow vulnerability in ABB Freelance controllers AC 700F (conroller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:  Freelance controllers AC 700F:  from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019 , through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;  Freelance controllers AC 900F:  through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.
History

Thu, 07 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Abb freelance Controllers Ac 700f
Abb freelance Controllers Ac 900f
CPEs cpe:2.3:h:abb:freelance_controllers_ac_700f:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:freelance_controllers_ac_900f:*:*:*:*:*:*:*:*
Vendors & Products Abb freelance Controllers Ac 700f
Abb freelance Controllers Ac 900f
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Abb Ac700f Ac700f Firmware Ac900f Freelance 2013 Freelance 2016 Freelance 2019 Freelance Controllers Ac 700f Freelance Controllers Ac 900f
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2024-11-07T15:48:28.656Z

Reserved: 2023-01-20T10:59:38.448Z

Link: CVE-2023-0426

cve-icon Vulnrichment

Updated: 2024-08-02T05:10:56.255Z

cve-icon NVD

Status : Modified

Published: 2023-08-07T06:15:11.167

Modified: 2024-11-21T07:37:09.567

Link: CVE-2023-0426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses