Executive brief
ABB Freelance Controller products are used to control and automate industrial processes in manufacturing and critical infrastructure environments. An improper handling of length parameters in these controllers can allow an attacker to send specially crafted network packets that cause the controller to malfunction, resulting in operational disruption or system instability.
Technical details
This vulnerability involves improper validation of length parameters in network communications, where a mismatch between declared and actual message lengths is not properly handled. The affected components process network-based protocol messages without sufficient length validation, allowing an attacker to send malformed packets. The vulnerability is network-accessible and does not require authentication. An attacker can exploit this to cause denial of service or potentially unexpected behavior in the industrial controller. Patches are available through ABB's advisory and should be applied to all affected product versions.
Affected products
- ABB Freelance Controller DCP through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1
- ABB Freelance Controller AC700 through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1
- ABB Freelance Controller AC800 through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1
- ABB Freelance Controller AC900 through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1
Timeline
- 2026-09-18: disclosed