PT-2018-3326 · Abb · Abb Esoms
Published
2018-08-10
·
Updated
2023-05-16
·
CVE-2018-14805
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ABB eSOMS version 6.0.2
Description:
The issue is related to the incorrect operation of the authentication mechanism in ABB eSOMS. This can allow a remote attacker to gain unauthorized access to the system if LDAP is configured for anonymous authentication and specific key values are present in the eSOMS web.config file. Both conditions must be met for the issue to be exploited.
Recommendations:
For ABB eSOMS version 6.0.2, consider disabling anonymous LDAP authentication and review the eSOMS web.config file to ensure that it does not contain the specific key values that can be exploited. Restrict access to the system until a proper fix can be applied.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abb Esoms