Length-parameter flaw enables unauthenticated DoS in ABB Freelance Controllers
CVSS 4.0
9.2critical
EPSS
—
Published
()
Modified
AI analysis
CVE-2023-5778 is an improper handling of length parameter inconsistency (CWE-130) in the communication handling of ABB Freelance Controllers, affecting the DCP, AC700, AC800, and AC900 controller families across Freelance releases from 2013 through 2019 SP1. A remote, unauthenticated attacker can send network traffic with inconsistent length parameters to the controller, triggering a fault with no user interaction or privileges required. Per the CVSS 4.0 vector (AV:N/AC:L/PR:N/UI:N with high availability and safety impact), the practical outcome is a crash or denial of service of the controller, and because these devices run industrial processes, the disruption can carry safety consequences in plants using Freelance as their DCS. All organizations running Freelance controllers on the affected releases are potentially exposed, though exploitation requires network reachability to the controller. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; ABB (the assigning CNA) has published the advisory.
What to do: Upgrade affected Freelance controller systems to a fixed release as specified in ABB's security advisory (anything beyond the listed releases through 2019 SP1). Until patched, restrict network access to controller communication ports via firewalls and OT/IT segmentation, and ensure the controllers are not reachable from untrusted networks or remote-access paths. Inventory plants for AC700/AC800/AC900/DCP controllers running Freelance 2013–2019 SP1 and treat an unexpected controller crash or reboot as a possible exploitation indicator.
Affected
ABB Freelance Controller DCP
All releases up to and including Freelance 2019 SP1 (through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1)
ABB Freelance Controller AC700
All releases up to and including Freelance 2019 SP1 (through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1)
ABB Freelance Controller AC800
All releases up to and including Freelance 2019 SP1 (through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1)
ABB Freelance Controller AC900
All releases up to and including Freelance 2019 SP1 (through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1)
Estimated exposure
Description
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.
≈20,000+ Freelance installations worldwide (tens of thousands of controllers); few likely internet-exposed — ABB has publicly marketed Freelance as having more than 20,000 installed systems, and each DCS installation typically runs multiple controllers, though these OT devices usually sit behind plant networks rather than directly on the internet.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Canada's Cyber Centre relayed ABB advisory AV26-942 addressing CVE-2023-5778, a missing length check flaw in Freelance Controller industrial devices.
The Canadian Centre for Cyber Security published advisory AV26-942 on September 18, 2026, noting that ABB released a security advisory addressing vulnerabilities in the Freelance Controller product line, affecting multiple versions and models. The cited flaw is CVE-2023-5778, described as a missing length check. The Cyber Centre encourages users and administrators to review ABB's advisory and apply updates as they become available.