Lucene search

K
cvelistABBCVELIST:CVE-2019-19002
HistoryApr 02, 2020 - 7:50 p.m.

CVE-2019-19002 ABB eSOMS X-XSS-Protection not enabled

2020-04-0219:50:02
CWE-79
CWE-16
ABB
www.cve.org
2

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

18.3%

For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.

CNA Affected

[
  {
    "product": "eSOMS",
    "vendor": "ABB",
    "versions": [
      {
        "status": "affected",
        "version": "4.0 to 6.0.2"
      }
    ]
  }
]

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

18.3%

Related for CVELIST:CVE-2019-19002