CVE-2023-1258: Abb Flow-X/c Firmware

Medium severity, CVSS 5.3. EPSS: 3.9% chance of exploitation in the next 30 days.

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

Affected products

  • Abb Flow-X/c Firmware: up to and including 3.2.6
  • Abb Flow-X/k Firmware: up to and including 3.2.6
  • Abb Flow-X/m Firmware: up to and including 3.2.6
  • Abb Flow-X/p Firmware: up to and including 3.2.6
  • Abb Flow-X/s Firmware: up to and including 3.2.6
  • Abb Flow-X/t Firmware: up to and including 3.2.6
  • Abb Flow-X/web Firmware: up to and including 3.2.6
  • Abb Flow-X R Firmware: up to and including 3.2.6

Published 2023-03-31. Last modified 2026-06-17.