Record summary

CVE-2023-1258 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 11, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Flow-X

Browse ABB / Flow-Xfirmware

Default status: unaffected

CVE ListBefore 4.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBABB FlowX v4.00 - Exposure of Sensitive InformationExploitDB exploitby Paul SmithNot analyzed1 file
ExploitDB

PoC details

References

3