CVE-2019-19000
published 2020-04-02CVE-2019-19000: For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.05%
60.5th percentile
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | esoms | — | — |
| abb | esoms | — | — |
| abb | esoms | — | — |
| hitachienergy | esoms | 4.0 – 6.0.3 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB eSOMS
cisa_ics·2020-03-31·CVSS 6.5
[MEDIUM] ABB eSOMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB eSOMS
Last RevisedMarch 31, 2020
Alert CodeICSA-20-072-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.6
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: ABB
- Equipment: eSOMS
- Vulnerabilities: Use of Web Browser Cache Containing Sensitive Information, Improper Restriction of Rendered UI Layers or Frames, Improper Neutralization of HTTP Headers for Scripting Syntax, Sensitive Cookie Without ‘HttpOnly’ Flag, Protection Mechanism Failure, Sensitive Cookie in HTTPS Session Without ‘Secure’ Attribute, Exposure of Sensitive Information to an Unauthorized Actor,
GHSA
GHSA-p65w-wgpq-h44r: For ABB eSOMS 4
ghsa_unreviewed·2022-05-24
CVE-2019-19000 [MEDIUM] CWE-200 GHSA-p65w-wgpq-h44r: For ABB eSOMS 4
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.
Suricata
ET EXPLOIT Observed Orange LiveBox Router Information Leakage Attempt (CVE-2018-20377)
suricata·2019-12-03·CVSS 9.8
CVE-2018-20377 [CRITICAL] ET EXPLOIT Observed Orange LiveBox Router Information Leakage Attempt (CVE-2018-20377)
ET EXPLOIT Observed Orange LiveBox Router Information Leakage Attempt (CVE-2018-20377)
Rule: alert http1 $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Observed Orange LiveBox Router Information Leakage Attempt (CVE-2018-20377)"; flow:established,to_server; http.request_line; content:"GET|20|"; startswith; content:"/get_getnetworkconf.cgi|20|HTTP/1.1"; fast_pattern; endswith; http.header_names; content:!"Referer"; reference:url,badpackets.net/over-19000-orange-livebox-adsl-modems-are-leaking-their-wifi-credentials; reference:cve,2018-20377; classtype:trojan-activity; sid:2029091; rev:3; metadata:affected_product Router, attack_target Client_Endpoint, created_at 2019_12_03, cve CVE_2018_20377, deployment Perimeter, signature_severity Major, updated_at 2024_04_04, reviewed_at 2024_02_2
No public exploits indexed.
No writeups or analysis indexed.
2020-04-02
Published