CVE-2019-19090Missing Encryption of Sensitive Data in Esoms

Severity
3.5LOWNVD
EPSS
0.2%
top 62.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateMay 24

Description

For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages2 packages

NVDhitachienergy/esoms4.06.0.2
CVEListV5abb/esoms4.0 to 6.0.2

🔴Vulnerability Details

2
GHSA
GHSA-w59j-v3f8-jgj6: For ABB eSOMS versions 42022-05-24
CVEList
ABB eSOMS: Secure Flag not set2020-04-02
CVE-2019-19090 — Missing Encryption of Sensitive Data | cvebase