PT-2023-8021 · Abb · Abb Freelance Controllers Ac 900F+1

Published

2023-08-07

·

Updated

2023-08-14

·

CVE-2023-0426

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions ABB Freelance controllers AC 700F versions 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1 ABB Freelance controllers AC 900F versions through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1
Description The issue is related to a Stack-based Buffer Overflow vulnerability in ABB Freelance controllers AC 700F and AC 900F. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible by sending a specially crafted HTTP request.
Recommendations For ABB Freelance controllers AC 700F versions 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1: Update to a version that resolves the reported vulnerabilities. For ABB Freelance controllers AC 900F versions through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1: Update to a version that resolves the reported vulnerabilities. As a temporary workaround, consider restricting access to the vulnerable controller modules until a patch is available.

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-09143
CVE-2023-0426

Affected Products

Abb Freelance Controllers Ac 700F
Abb Freelance Controllers Ac 900F