Executive brief
ABB Freelance, a distributed control system used for process automation in industrial environments, contains a security vulnerability that could allow an attacker to bypass authentication. An attacker with local access to the system could potentially gain unauthorized control or modify system configurations. This could lead to operational disruptions or unauthorized changes to industrial processes.
Technical details
An authentication bypass vulnerability (CWE-305) exists in ABB Freelance due to a primary weakness in the authentication mechanism. The vulnerability allows a local attacker with low privileges to bypass authentication procedures. According to the CVSS vector, the attack requires local access and no user interaction, potentially allowing the attacker to achieve high integrity impact and low confidentiality and availability impact. Affected versions range from Freelance 2013 through Freelance 2024. Users are advised to consult ABB advisory 7PAA020361 for specific mitigation or patching instructions.
Affected products
- ABB Freelance through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024
Timeline
- 2026-06-11: advisory: NVD published the CVE record based on ABB's disclosure.