vendor:
ABB FlowX
by:
Paul Smith
5.5
CVSS
MEDIUM
Exposure of Sensitive Information
200
CWE
Product Name: ABB FlowX
Affected Version From: ABB Flow-X all versions before V4.00
Affected Version To: V4.00
Patch Exists: YES
Related CWE: CVE-2023-1258
CPE: ABB Flow-X
Platforms Tested: Kali Linux
2023
ABB FlowX v4.00 – Exposure of Sensitive Information
This exploit allows an attacker to expose sensitive information in ABB FlowX v4.00. By sending a specific request, the attacker can retrieve user login information from the system.
Mitigation:
To mitigate this vulnerability, it is recommended to update ABB FlowX to version 4.00 or later. Additionally, access to the system should be restricted to authorized personnel only.