5.3

CVE-2023-1258

Exploit

Flow-X disclosure of sensitive information to unauthenticated users

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Abb ≫ Flow-x/m Firmware Version <= 3.2.6
   Abb ≫ Flow-x/m Version -
Abb ≫ Flow-x/c Firmware Version <= 3.2.6
   Abb ≫ Flow-x/c Version -
Abb ≫ Flow-x/k Firmware Version <= 3.2.6
   Abb ≫ Flow-x/k Version -
Abb ≫ Flow-x/s Firmware Version <= 3.2.6
   Abb ≫ Flow-x/s Version -
Abb ≫ Flow-x/p Firmware Version <= 3.2.6
   Abb ≫ Flow-x/p Version -
Abb ≫ Flow-x R Firmware Version <= 3.2.6
   Abb ≫ Flow-x R Version -
Abb ≫ Flow-x/t Firmware Version <= 3.2.6
   Abb ≫ Flow-x/t Version -
Abb ≫ Flow-x/web Firmware Version <= 3.2.6
   Abb ≫ Flow-x/web Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.88% 0.889
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cybersecurity@ch.abb.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://packetstormsecurity.com/files/173610/ABB-FlowX-4.00-Information-Disclosure.html
Third Party Advisory
Exploit
VDB Entry
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A9754&LanguageCode=en&DocumentPartId=&Action=Launch
Vendor Advisory