vendor:
ABB Cylon FLXeon Controller Series
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: ABB Cylon FLXeon Controller Series
Affected Version From: FLXeon Series (FBXi Series, FBTi Series, FBVi Series), CBX Series (FLX Series), CBT Series, CBV Series
Affected Version To: Firmware version 9.3.4
Patch Exists: NO
Related CWE: CVE-2024-48852
CPE: abb:cylon_flxeon:9.3.4
Platforms Tested: Linux, NodeJS, Express
2024
ABB Cylon FLXeon 9.3.4 – System Logs Information Disclosure
An authenticated attacker can access critical information via the system logs page of ABB Cylon FLXeon controllers, including the OpenSSL password for stored certificates. This data exposure can lead to potential attacks like decrypting encrypted communications, impersonation, or gaining deeper system access.
Mitigation:
Upgrade the firmware to version 9.3.5 or higher to address this vulnerability and avoid unauthorized access to sensitive information.