Authentication and Authorization Issues
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.9%
from disclosure to weapon72 days
Published on NVDJan 29
1st PoC+72d
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short
FLXEON fails to properly validate the origin of WebSocket connections, allowing attackers to make unauthorized HTTPS requests by exploiting weak session management. This could let someone perform actions on behalf of a legitimate user without their knowledge.
Technical detail
A missing Origin validation vulnerability in FLXEON's WebSocket implementation allows cross-site request forgery (CSRF) attacks. The insufficient session management mechanism fails to verify the legitimacy of connection origins, enabling an attacker to trigger unauthorized HTTPS requests in the context of an authenticated user's session. Affected versions: up to 9.3.4.
Summary generated and translated by AI from the official description.
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
ABB · FLXEONpublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/52184unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.