CVE-2023-0425
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/08/2023
Last modified:
14/08/2023
Description
<br />
ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves<br />
the reported vulnerabilities in the product versions under maintenance.<br />
An attacker who successfully exploited one or more of these vulnerabilities could cause the product to<br />
stop or make the product inaccessible. <br />
<br />
Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:<br />
<br />
Freelance controllers AC 700F: <br />
<br />
from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1; <br />
<br />
Freelance controllers AC 900F: <br />
<br />
Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.<br />
<br />
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:abb:ac700f_firmware:*:*:*:*:*:*:*:* | 9.0.0 (including) | 9.2.0 (excluding) |
| cpe:2.3:o:abb:ac700f_firmware:9.2.0:-:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:ac700f_firmware:9.2.0:sp1:*:*:*:*:*:* | ||
| cpe:2.3:h:abb:ac700f:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:freelance_2013:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:freelance_2013:-:sp1:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:freelance_2016:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:freelance_2016:-:sp1:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:freelance_2019:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:freelance_2019:-:sp1:*:*:*:*:*:* | ||
| cpe:2.3:o:abb:freelance_2019:-:sp1_fp1:*:*:*:*:*:* | ||
| cpe:2.3:h:abb:ac700f:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:abb:ac900f:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



