Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23527 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
Fixes

Solution

No solution given by the vendor.


Workaround

To minimize the risk of unauthorized access to sensitive information, ABB recommends to only operate Flow-X flow computers in secure networks. Additionally, ABB recommends that HTTPS is used to communicate with the Flow-X web server. HTTPS support has been implemented since version 1.2.2 (available as of June 2016) and is enabled by default since version 3.2.0 (available as of September 2020). To minimize the risk of exposed security information on one device leading to unauthorized access on other devices, ABB recommends that customers change the usernames and passwords that are part of the standard application and to use different usernames and password on different devices

History

Thu, 13 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0. Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

Tue, 11 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2025-02-13T16:39:19.647Z

Reserved: 2023-03-07T16:57:05.254Z

Link: CVE-2023-1258

cve-icon Vulnrichment

Updated: 2024-08-02T05:40:59.772Z

cve-icon NVD

Status : Modified

Published: 2023-03-31T08:15:06.397

Modified: 2025-02-13T17:15:57.873

Link: CVE-2023-1258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.