Description
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.

This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
Published: 2026-09-18
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Potential Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an improper handling of length parameters, creating a situation where the system may read or write beyond the intended memory bounds. Such a flaw can lead to memory corruption, which in many scenarios can be leveraged for arbitrary code execution. In the absence of explicit attack vector details, it is inferred that an attacker could trigger the flaw by supplying malicious input that exploits the length‑check inconsistency.

Affected Systems

The affected products are ABB Freelance Controller DCP, AC700, AC800, and AC900. All versions through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1 are impacted.

Risk and Exploitability

The CVSS score of 9.2 indicates a critical severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, which suggests that there is no current widely reported exploitation. Nonetheless, the severity rating implies a high potential for exploitation if the flaw can be reached, possibly via remote network interactions with the controllers or through local input channels. The likely attack vector is that an attacker could trigger the flaw by supplying malicious input that exploits the length‑check inconsistency. The EPSS score of < 1% indicates a low probability of exploitation at present, but the critical CVSS recommends immediate attention.

Generated by OpenCVE AI on September 19, 2026 at 19:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest ABB firmware update or patch for the affected controller models.
  • Restrict network access to the controllers by limiting exposure to trusted IP ranges, using dedicated VLANs or firewall rules.
  • Monitor controller logs for anomalous activity or repeated failures that could indicate exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Abb
Abb freelance Controller Ac700
Abb freelance Controller Ac800
Abb freelance Controller Ac900
Abb freelance Controller Dcp
Vendors & Products Abb
Abb freelance Controller Ac700
Abb freelance Controller Ac800
Abb freelance Controller Ac900
Abb freelance Controller Dcp

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
Title Missing Length Check
Weaknesses CWE-130
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/AU:Y/R:U/V:C/RE:H'}


Subscriptions

Abb Freelance Controller Ac700 Freelance Controller Ac800 Freelance Controller Ac900 Freelance Controller Dcp
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2026-09-18T14:31:45.340Z

Reserved: 2023-10-26T01:57:08.369Z

Link: CVE-2023-5778

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:15.698Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:17:14.870

Modified: 2026-09-18T17:49:08.457

Link: CVE-2023-5778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:43Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency