CVE-2023-1258: Flow-X disclosure of sensitive information to unauthenticated users
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
Credit
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1258?
CVE-2023-1258 is a vulnerability that allows the exposure of sensitive information to an unauthorized actor in ABB Flow-X firmware on Flow-X embedded hardware (web service modules).
Which software versions are affected by CVE-2023-1258?
CVE-2023-1258 affects Flow-X firmware versions before 4.0.
What is the severity of CVE-2023-1258?
CVE-2023-1258 has a severity rating of 5.3, which is considered medium.
How does CVE-2023-1258 vulnerability allow Footprinting?
CVE-2023-1258 vulnerability in ABB Flow-X firmware allows an unauthorized actor to conduct Footprinting, which involves gathering information about a target system.
How can I fix CVE-2023-1258 vulnerability?
To fix CVE-2023-1258 vulnerability, it is recommended to update to Flow-X firmware version 4.0 or later.