packetstormsecurity.com
http://packetstormsecurity.com/files/173610/ABB-FlowX-4.00-Information-Disclosure.html CVE-2023-1258
MEDIUM
Flow-X disclosure of sensitive information to unauthenticated users
Record summary
CVE-2023-1258 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 11, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 4.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBABB FlowX v4.00 - Exposure of Sensitive InformationExploitDB exploitby Paul SmithNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-1258 search.abb.com
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A9754&LanguageCode=en&DocumentPartId=&Action=Launch