Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
Published: 2023-03-31
Score: 5.3 Medium
EPSS: 11.6% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

To minimize the risk of unauthorized access to sensitive information, ABB recommends to only operate Flow-X flow computers in secure networks. Additionally, ABB recommends that HTTPS is used to communicate with the Flow-X web server. HTTPS support has been implemented since version 1.2.2 (available as of June 2016) and is enabled by default since version 3.2.0 (available as of September 2020). To minimize the risk of exposed security information on one device leading to unauthorized access on other devices, ABB recommends that customers change the usernames and passwords that are part of the standard application and to use different usernames and password on different devices

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-23527 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
History

Thu, 13 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0. Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

Tue, 11 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Abb Flow-x\/c Flow-x\/c Firmware Flow-x\/k Flow-x\/k Firmware Flow-x\/m Flow-x\/m Firmware Flow-x\/p Flow-x\/p Firmware Flow-x\/s Flow-x\/s Firmware Flow-x\/t Flow-x\/t Firmware Flow-x\/web Flow-x\/web Firmware Flow-x R Flow-x R Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2025-02-13T16:39:19.647Z

Reserved: 2023-03-07T16:57:05.254Z

Link: CVE-2023-1258

cve-icon Vulnrichment

Updated: 2024-08-02T05:40:59.772Z

cve-icon NVD

Status : Modified

Published: 2023-03-31T08:15:06.397

Modified: 2025-02-13T17:15:57.873

Link: CVE-2023-1258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses