CVE-2023-0425CWE-839

Buffer overflow in global memory region

High · published August 7, 2023

CVSS v3.1
8.6
EPSS
0%
Percentile
39.1
In the wild
Unconfirmed
What it is

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves

the reported vulnerabilities in the product versions under maintenance.

An attacker who successfully exploited one or more of these vulnerabilities could cause the product to

stop or make the product inaccessible.

Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:

Freelance controllers AC 700F:

from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;

Freelance controllers AC 900F:

Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

The record
Technical detail
CVSS v3.1
8.6 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CVSS v4.0
Not supplied
EPSS
0.00470 · 39.1th percentile
Weakness
CWE-839 · Numeric Range Comparison Without Minimum Check
Published
2023-08-07T05:06Z
EPSS history
Timeline
  • 07 AUG 05:06Z
    Buffer overflow in global memory region
    cvelistv5