CVE-2018-14805
published 2018-08-29CVE-2018-14805: ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the…
PriorityP359critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.81%
91.0th percentile
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachienergy | esoms | — | — |
| ics-cert | abb_esoms | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB eSOMS (Update A)
cisa_ics·2018-08-28·CVSS 9.8
[CRITICAL] ABB eSOMS (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB eSOMS (Update A)
Last RevisedOctober 02, 2018
Alert CodeICSA-18-240-04
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: ABB
- Equipment: eSOMS
- Vulnerability: Improper Authentication
## 2 UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-18-240-04 ABB eSOMS that was published August 28, 2018, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability requires an attacker to discover a valid user account, which could be used t
GHSA
GHSA-qr8c-f5qw-7crq: ABB eSOMS version 6
ghsa_unreviewed·2022-05-13
CVE-2018-14805 [CRITICAL] CWE-287 GHSA-qr8c-f5qw-7crq: ABB eSOMS version 6
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105169https://ics-cert.us-cert.gov/advisories/ICSA-18-240-04https://search.abb.com/library/Download.aspx?DocumentID=9AKK107046A5821&LanguageCode=en&DocumentPartId=&Action=Launchhttp://www.securityfocus.com/bid/105169https://ics-cert.us-cert.gov/advisories/ICSA-18-240-04https://search.abb.com/library/Download.aspx?DocumentID=9AKK107046A5821&LanguageCode=en&DocumentPartId=&Action=Launch
2018-08-29
Published