peter bassill · operator
$ cve CVE-2023-1258 JSON

CVE-2023-1258 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS3.88% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2023-03-31
Last modified2026-06-17

Affected (16)

VendorProduct
abbflow-x r
abbflow-x r firmware
abbflow-x\/c
abbflow-x\/c firmware
abbflow-x\/k
abbflow-x\/k firmware
abbflow-x\/m
abbflow-x\/m firmware
abbflow-x\/p
abbflow-x\/p firmware
abbflow-x\/s
abbflow-x\/s firmware
abbflow-x\/t
abbflow-x\/t firmware
abbflow-x\/web
abbflow-x\/web firmware

Public exploits

SourceTitleDate
exploit-dbABB FlowX v4.00 - Exposure of Sensitive Information2023-07-19

References

→ the Explorer  ·  watch your stack  ·  NVD