CVE-2023-0425
Last modified
CVE-2023-0425 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible. Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects: Freelance controllers AC 700F: from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1; Freelance controllers AC 900F: Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1. . EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible. Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects: Freelance controllers AC 700F: from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1; Freelance controllers AC 900F: Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Abb | Ac700f Firmware | >= 9.0.0, < 9.2.0 |
| Abb | Ac700f Firmware | 9.2.0 |
| Abb | Freelance 2013 | All versions |
| Abb | Freelance 2016 | All versions |
| Abb | Freelance 2019 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-0425?
How severe is CVE-2023-0425?
How do I fix CVE-2023-0425?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-0419The Shortcode for Font Awesome WordPress plugin before 1.4.1…5.4
- CVE-2023-0420The Custom Post Type and Taxonomy GUI Manager WordPress plug…4.8
- CVE-2023-0421The Cloud Manager WordPress plugin through 1.0 does not sani…6.1
- CVE-2023-0422The Article Directory WordPress plugin through 1.3 does not …4.8
- CVE-2023-0423The WordPress Amazon S3 Plugin WordPress plugin before 1.6 d…4.8
- CVE-2023-0424The MS-Reviews WordPress plugin through 1.5 does not sanitis…5.4
- CVE-2023-0426 ABB is aware of vulnerabilities in the product versions lis…7.5
- CVE-2023-0428The Watu Quiz WordPress plugin before 3.3.8.2 does not sanit…6.1
- CVE-2023-0429The Watu Quiz WordPress plugin before 3.3.8.2 does not sanit…4.8
- CVE-2023-0430Certificate OCSP revocation status was not checked when veri…6.5
- CVE-2023-0431The File Away WordPress plugin through 3.9.9.0.1 does not va…5.4
- CVE-2023-0432 The web configuration service of the affected device contai…9
Are you affected by CVE-2023-0425?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
