CVE-2019-19091

Severity
4.3MEDIUM
EPSS
0.2%
top 54.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateMay 24

Description

For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDhitachienergy/esoms4.06.0.3
CVEListV5abb/esoms4.0 to 6.0.3

🔴Vulnerability Details

2
GHSA
GHSA-5cp6-m9h7-hx26: For ABB eSOMS versions 42022-05-24
CVEList
ABB eSOMS: HTTP response information leakage2020-04-02
CVE-2019-19091 (MEDIUM CVSS 4.3) | For ABB eSOMS versions 4.0 to 6.0.3 | cvebase.io