Impact
The vulnerability arises from an improper handling of length parameters, creating a situation where the system may read or write beyond the intended memory bounds. Such a flaw can lead to memory corruption, which in many scenarios can be leveraged for arbitrary code execution. In the absence of explicit attack vector details, it is inferred that an attacker could trigger the flaw by supplying malicious input that exploits the length‑check inconsistency.
Affected Systems
The affected products are ABB Freelance Controller DCP, AC700, AC800, and AC900. All versions through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1 are impacted.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, which suggests that there is no current widely reported exploitation. Nonetheless, the severity rating implies a high potential for exploitation if the flaw can be reached, possibly via remote network interactions with the controllers or through local input channels. The likely attack vector is that an attacker could trigger the flaw by supplying malicious input that exploits the length‑check inconsistency. The EPSS score of < 1% indicates a low probability of exploitation at present, but the critical CVSS recommends immediate attention.
OpenCVE Enrichment