PT-2020-6882 · Abb · Abb Esoms

CVE-2019-19090

·

Published

2020-02-17

·

Updated

2023-05-16

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ABB eSOMS versions 4.0 to 6.0.2
Description The issue is related to the absence of the Secure Flag in the HTTP response header, which may allow unencrypted connections to access cookie information, making it susceptible to eavesdropping. This could enable a remote attacker to gain unauthorized access to protected information.
Recommendations For ABB eSOMS versions 4.0 to 6.0.2, consider implementing HTTPS to encrypt connections and prevent eavesdropping. As a temporary workaround, restrict access to sensitive information until a patch is available. Ensure that all connections to the ABB eSOMS use encrypted protocols to protect cookie information.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03074
CVE-2019-19090

Affected Products

Abb Esoms