Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-5778— Missing Length Check

Quick assessment

Affected
ABB Freelance Controller DCP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ABB Freelance 控制器 DCP、AC700、AC800 和 AC900 中存在长度参数处理不当导致的漏洞(length 参数处理不一致)。 该问题影响以下版本: Freelance 控制器 DCP:2013、2013 SP1、2016、2016 SP1、2019 和 2019 SP1; Freelance 控制器 AC700:2013、2013 SP1、2016、2016 SP1、2019 和 2019 SP1; Freelance 控制器 AC800:2013、2013 SP1、2016、2016 S

CVSS 7.5 · High EPSS 0.29% · P22

Affected Version Matrix 32

VendorProduct Version RangeStatus
ABB Freelance Controller AC700 ≤ 2013 affected
2013 SP1 affected
2016 affected
2016 SP1 affected
2019 affected
2019 SP1 affected
2019 SP1 FP1 unaffected
2024 unaffected
ABB Freelance Controller AC800 ≤ 2013 affected
2013 SP1 affected
2016 affected
2016 SP1 affected
2019 affected
2019 SP1 affected
2019 SP1 FP1 unaffected
2024 unaffected
ABB Freelance Controller AC900 ≤ 2013 affected
2013 SP1 affected
2016 affected
2016 SP1 affected
2019 affected
2019 SP1 affected
2019 SP1 FP1 unaffected
2024 unaffected
ABB Freelance Controller DCP ≤ 2013 affected
2013 SP1 affected
2016 affected
2016 SP1 affected
2019 affected
2019 SP1 affected
2019 SP1 FP1 unaffected
2024 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-5778

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing Length Check
Source: CVE Program / CVE List V5
Vulnerability Description
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
长度参数不一致性处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ABB Freelance Controller DCP 0 ~ 2013 -
ABB Freelance Controller AC700 0 ~ 2013 -
ABB Freelance Controller AC800 0 ~ 2013 -
ABB Freelance Controller AC900 0 ~ 2013 -

II. Public POCs for CVE-2023-5778

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-5778

登录查看更多情报信息。

Other References for CVE-2023-5778 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-5778

No comments yet


Leave a comment