ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An update is available that resolves the reported vulnerability in the product versions under maintenance.
An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.
CVE-2023-5778. An attacker could exploit this vulnerability by sending a specially crafted message to the controller, causing the controller to stop.
// Remediations (3)
Workaround: For Freelance system version >= Freelance 2016 and Freelance controllers AC 700 and AC 900 (by using
For Freelance system version >= Freelance 2016 and Freelance controllers AC 700 and AC 900 (by using the Display Unit) there is the possibility to activate the Download-Protection (disabled Download) on the controller.
Download-Protection for the AC 700 Controller:
Use the “Mounting_and_Installation_AC_700F_Controller” / “M&I - AC 700F Controller” (Englisch) or Montage_und_Installation_AC_700F_Controller” / “M&I - AC 700F Controller” (German) User Manual PDF. In the “8.3.2 Online functions” / “8.3.2 Online-Funktionen” section look for the desired action “Locking the AC 700F for application and firmware downloads” / “AC 700F für Applikations und Firm-ware-Download sperren”. When the locking is enabled the controller is not vulnerable any more against this know issue.
Download-Protection for the AC 900 Controller:
Use the “Mounting_and_Installation_AC_700F_Controller” / “M&I - AC 700F Controller” (Englisch) or “Montage_und_Installation_AC_700F_Controller” / “M&I - AC 700F Controller” (German) User Manual PDF. In the “Section 8 - Service -> Online functions of the display unit -> Controller menu -> F2 - Security -> F2 function: Download enabled/disabled” / “Kapitel 8 - Service -> Online-Funktionen der Display-Unit -> Controller-Menü -> F2 - Security -> Funktion F2: Download freigegeben/gesperrt” there is the Download-Protection described. When the Download is disabled the controller is not vulnerable any more against this know issue.
Mitigation: Refer to section “General security recommendations” for further advice on how to keep your system se
Refer to section “General security recommendations” for further advice on how to keep your system secure, as well checking the section “Workarounds”.
Patch: The Freelance system shall be used as described in the manual 3BDD012560-111 “Getting Started” chapt
The Freelance system shall be used as described in the manual 3BDD012560-111 “Getting Started” chapter 1.2.6.
The issue is corrected in following product versions:
• Freelance 2013 SP1 RU06 and higher RUs for that version
• Freelance 2016 SP1 RU07 and higher RUs for that version
• Freelance 2019 SP1 RU03 and higher RUs for that version
This vulnerability is corrected in the product versions from Freelance 2019 SP1 FP1 on. This vulnerability does not exist with Freelance 2019 SP1 FP1 and later.
ABB recommends that customers apply the update at earliest convenience. Users who are unable to install the updates should immediately look to implement the Mitigation listed as this will block an attacker’s ability to compromise their installations.