CVE-2018-14805Improper Authentication in ABB Esoms

Severity
9.8CRITICALNVD
EPSS
1.3%
top 20.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 13

Description

ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5ics-cert/abb_esomsVersion 6.0.2

🔴Vulnerability Details

2
GHSA
GHSA-qr8c-f5qw-7crq: ABB eSOMS version 62022-05-13
CVEList
CVE-2018-14805: ABB eSOMS version 62018-08-29
CVE-2018-14805 — Improper Authentication in ABB Esoms | cvebase