CVE-2019-19001
published 2020-04-02CVE-2019-19001: For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.53%
72.0th percentile
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | esoms | — | — |
| hitachienergy | esoms | 4.0 – 6.0.2 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB eSOMS
cisa_ics·2020-03-31·CVSS 6.5
[MEDIUM] ABB eSOMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB eSOMS
Last RevisedMarch 31, 2020
Alert CodeICSA-20-072-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.6
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: ABB
- Equipment: eSOMS
- Vulnerabilities: Use of Web Browser Cache Containing Sensitive Information, Improper Restriction of Rendered UI Layers or Frames, Improper Neutralization of HTTP Headers for Scripting Syntax, Sensitive Cookie Without ‘HttpOnly’ Flag, Protection Mechanism Failure, Sensitive Cookie in HTTPS Session Without ‘Secure’ Attribute, Exposure of Sensitive Information to an Unauthorized Actor,
GHSA
GHSA-g26h-g3h8-pq5x: For ABB eSOMS versions 4
ghsa_unreviewed·2022-05-24
CVE-2019-19001 [MEDIUM] CWE-1021 GHSA-g26h-g3h8-pq5x: For ABB eSOMS versions 4
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-02
Published