Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2023-5778: ABB Freelance Controllers may accept incorrect data length

CVE-2023-5778 · published 12 days ago
Summary

The DCP, AC700, AC800 and AC900 models of ABB Freelance Controller can be tricked into processing data whose length doesn’t match what the system expects. This mismatch could let an attacker cause the controller to behave unpredictably or crash, potentially disrupting operations. Update the controllers to the latest firmware or apply the vendor’s recommended patch to fix the length‑checking logic.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
abb freelance controller dcp <= 2013
abb freelance controller ac700 <= 2013
abb freelance controller ac800 <= 2013
abb freelance controller ac900 <= 2013
Original advisory text
Missing Length Check
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.

This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-130Improper Handling of Length Parameter Inconsistency
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Sources
CVE-2023-5778 · NVD
CVE-2023-5778 · MITRE
Track software like this
Free during beta