Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2023-5778: ABB Freelance Controllers may accept incorrect data length
CVE-2023-5778 · published 12 days ago
Summary
The DCP, AC700, AC800 and AC900 models of ABB Freelance Controller can be tricked into processing data whose length doesn’t match what the system expects. This mismatch could let an attacker cause the controller to behave unpredictably or crash, potentially disrupting operations. Update the controllers to the latest firmware or apply the vendor’s recommended patch to fix the length‑checking logic.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| abb | freelance controller dcp | <= 2013 |
| abb | freelance controller ac700 | <= 2013 |
| abb | freelance controller ac800 | <= 2013 |
| abb | freelance controller ac900 | <= 2013 |
Original advisory text
Missing Length Check
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.
This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Type
CWE-130Improper Handling of Length Parameter Inconsistency
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta