ABB Freelance Security Lock

View CSAF

Summary

Successful exploitation of this vulnerability could allow access to underlying OS functions even when Freelance Operations is active, depending on system configuration and user permissions.

The following versions of ABB Freelance Security Lock are affected:

  • ABB System Version (<=Freelance 2013) installed with ABB Freelance Security Lock(All versions) vers:all/* 
  • ABB System Version (Freelance 2013 SP1) installed with ABB Freelance Security Lock(All versions) vers:all/* 
  • ABB System Version (Freelance 2016) installed with ABB Freelance Security Lock(All versions) vers:all/* 
  • ABB System Version (Freelance 2016 SP1) installed with ABB Freelance Security Lock(All versions) vers:all/* 
  • ABB System Version (Freelance 2019) installed with ABB Freelance Security Lock(All versions) vers:all/* 
  • ABB System Version (Freelance 2019 SP1) installed with ABB Freelance Security Lock(All versions) vers:all/* 
  • ABB System Version (Freelance 2019 SP1 FP1) installed with ABB Freelance Security Lock(All versions) vers:all/* 
  • ABB System Version (Freelance 2024) installed with ABB Freelance Security Lock(All versions) vers:all/* 
CVSS Vendor Equipment Vulnerabilities
v3 6.6 ABB ABB Freelance Security Lock Authentication Bypass by Primary Weakness

Background

  • Critical Infrastructure Sectors: Critical Manufacturing
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Switzerland

Vulnerabilities

Expand All +

CVE-2025-7064

An attacker is able to attack Freelance user management when Security Lock is enabled. The precondition is that the attacker bypasses Freelance Operations which blocks access to the Windows operating system. This bypass can be achieved via undocumented or special key combinations available on modern keyboards. These combinations may allow access to underlying OS functions even when Freelance Operations is active, depending on system configuration and user permissions.

View CVE Details


Affected Products

ABB Freelance Security Lock
Vendor:
ABB
Product Version:
ABB ABB System Version (<=Freelance 2013) installed with ABB Freelance Security Lock(All versions): vers:all/*, ABB ABB System Version (Freelance 2013 SP1) installed with ABB Freelance Security Lock(All versions): vers:all/*, ABB ABB System Version (Freelance 2016) installed with ABB Freelance Security Lock(All versions): vers:all/*, ABB ABB System Version (Freelance 2016 SP1) installed with ABB Freelance Security Lock(All versions): vers:all/*, ABB ABB System Version (Freelance 2019) installed with ABB Freelance Security Lock(All versions): vers:all/*, ABB ABB System Version (Freelance 2019 SP1) installed with ABB Freelance Security Lock(All versions): vers:all/*, ABB ABB System Version (Freelance 2019 SP1 FP1) installed with ABB Freelance Security Lock(All versions): vers:all/*, ABB ABB System Version (Freelance 2024) installed with ABB Freelance Security Lock(All versions): vers:all/*
Product Status:
known_affected
Remediations

Mitigation
For more information see the associated ABB PSIRT security advisory 7PAA020361 PDF Version (https://search.abb.com/library/Download.aspx?DocumentID=7PAA020361&LanguageCode=en&DocumentPartId=&Action=Launch), CSAF Version (https://psirt.abb.com/csaf/2026/7paa020361.json).
https://search.abb.com/library/Download.aspx?DocumentID=7PAA020361&LanguageCode=en&DocumentPartId=&Action=Launch

Mitigation
For more information see the associated ABB PSIRT security advisory 7PAA020361 PDF Version (https://search.abb.com/library/Download.aspx?DocumentID=7PAA020361&LanguageCode=en&DocumentPartId

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from All CISA Advisories

Read the original article: