PT-2020-6875 · Abb · Abb Esoms

Published

2020-02-17

·

Updated

2023-05-16

·

CVE-2019-19096

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ABB eSOMS versions 6.0 through 6.0.2
Description The issue is related to the storage of credentials in a recoverable format by the Redis data structure component used in ABB eSOMS. This can potentially allow an attacker to gain unauthorized access to protected information if they have file system access, compromising the confidentiality of the credentials.
Recommendations For ABB eSOMS versions 6.0 through 6.0.2, consider restricting access to the Redis data structure component to minimize the risk of exploitation. As a temporary workaround, limit file system access to authorized personnel only until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2023-02924
CVE-2019-19096

Affected Products

Abb Esoms