Information disclosures
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 2.4%
from disclosure to weapon72 days
Published on NVDJan 29
1st PoC+72d
exploitation probability
2.4%top 18% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short
FLEXON versions up to 9.3.4 accidentally log sensitive information that can be exposed through HTTPS connections. This means confidential data might be visible to anyone who can access the log files.
Technical detail
CWE-532 vulnerability in FLEXON ≤9.3.4 allows sensitive information disclosure via HTTPS access due to improper logging practices. Attackers with access to log files (local or remote) can retrieve confidential data that should not be logged. The vulnerability affects availability and confidentiality of sensitive information.
Summary generated and translated by AI from the official description.
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.
This issue affects FLXEON through <= 9.3.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
ABB · FLXEONpublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/52178unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.