// For flags

CVE-2023-0426

Stack overflow in filename or in boundary

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves
the reported vulnerabilities in the product versions under maintenance.
An attacker who successfully exploited one or more of these vulnerabilities could cause the product to
stop or make the product inaccessible.



Stack-based Buffer Overflow vulnerability in ABB Freelance controllers AC 700F (conroller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:

 Freelance controllers AC 700F: 

from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019 , through Freelance 2019 SP1, through Freelance 2019 SP1 FP1; 




Freelance controllers AC 900F: 

through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

*Credits: ABB thanks Nataliya Tlyapova and Denis Goryushev (Positive Technologies) for responsibly reporting the vulnerabilities and working with us as we addressed them.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-01-20 CVE Reserved
  • 2023-08-07 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Abb
Search vendor "Abb"
Ac700f Firmware
Search vendor "Abb" for product "Ac700f Firmware"
>= 9.0.0 < 9.2.0
Search vendor "Abb" for product "Ac700f Firmware" and version " >= 9.0.0 < 9.2.0"
-
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Ac700f Firmware
Search vendor "Abb" for product "Ac700f Firmware"
9.2.0
Search vendor "Abb" for product "Ac700f Firmware" and version "9.2.0"
-
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Ac700f Firmware
Search vendor "Abb" for product "Ac700f Firmware"
9.2.0
Search vendor "Abb" for product "Ac700f Firmware" and version "9.2.0"
sp1
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2013
Search vendor "Abb" for product "Freelance 2013"
--
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2013
Search vendor "Abb" for product "Freelance 2013"
--
Affected
in Abb
Search vendor "Abb"
Ac900f
Search vendor "Abb" for product "Ac900f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2013
Search vendor "Abb" for product "Freelance 2013"
-sp1
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2013
Search vendor "Abb" for product "Freelance 2013"
-sp1
Affected
in Abb
Search vendor "Abb"
Ac900f
Search vendor "Abb" for product "Ac900f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2016
Search vendor "Abb" for product "Freelance 2016"
--
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2016
Search vendor "Abb" for product "Freelance 2016"
--
Affected
in Abb
Search vendor "Abb"
Ac900f
Search vendor "Abb" for product "Ac900f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2016
Search vendor "Abb" for product "Freelance 2016"
-sp1
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2016
Search vendor "Abb" for product "Freelance 2016"
-sp1
Affected
in Abb
Search vendor "Abb"
Ac900f
Search vendor "Abb" for product "Ac900f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2019
Search vendor "Abb" for product "Freelance 2019"
--
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2019
Search vendor "Abb" for product "Freelance 2019"
--
Affected
in Abb
Search vendor "Abb"
Ac900f
Search vendor "Abb" for product "Ac900f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2019
Search vendor "Abb" for product "Freelance 2019"
-sp1
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2019
Search vendor "Abb" for product "Freelance 2019"
-sp1
Affected
in Abb
Search vendor "Abb"
Ac900f
Search vendor "Abb" for product "Ac900f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2019
Search vendor "Abb" for product "Freelance 2019"
-sp1_fp1
Affected
in Abb
Search vendor "Abb"
Ac700f
Search vendor "Abb" for product "Ac700f"
--
Safe
Abb
Search vendor "Abb"
Freelance 2019
Search vendor "Abb" for product "Freelance 2019"
-sp1_fp1
Affected
in Abb
Search vendor "Abb"
Ac900f
Search vendor "Abb" for product "Ac900f"
--
Safe