8.6

CVE-2023-0426

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves
the reported vulnerabilities in the product versions under maintenance.
An attacker who successfully exploited one or more of these vulnerabilities could cause the product to
stop or make the product inaccessible. 



Stack-based Buffer Overflow vulnerability in ABB Freelance controllers AC 700F (conroller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:

 Freelance controllers AC 700F: 

from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019 , through Freelance 2019 SP1, through Freelance 2019 SP1 FP1; 




Freelance controllers AC 900F: 

through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AbbAc700f Firmware Version >= 9.0.0 < 9.2.0
   AbbAc700f Version-
AbbAc700f Firmware Version9.2.0 Update-
   AbbAc700f Version-
AbbAc700f Firmware Version9.2.0 Updatesp1
   AbbAc700f Version-
AbbFreelance 2013 Version-
   AbbAc700f Version-
   AbbAc900f Version-
AbbFreelance 2013 Version- Updatesp1
   AbbAc700f Version-
   AbbAc900f Version-
AbbFreelance 2016 Version-
   AbbAc700f Version-
   AbbAc900f Version-
AbbFreelance 2016 Version- Updatesp1
   AbbAc700f Version-
   AbbAc900f Version-
AbbFreelance 2019 Version-
   AbbAc700f Version-
   AbbAc900f Version-
AbbFreelance 2019 Version- Updatesp1
   AbbAc700f Version-
   AbbAc900f Version-
AbbFreelance 2019 Version- Updatesp1_fp1
   AbbAc700f Version-
   AbbAc900f Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.404
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cybersecurity@ch.abb.com 8.6 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).