First published: Thu Apr 02 2020(Updated: )
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachienergy Esoms | >=4.0<=6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this ABB eSOMS vulnerability is CVE-2019-19090.
The impact of the CVE-2019-19090 vulnerability is that unencrypted connections might access the cookie information, making it susceptible to eavesdropping.
ABB eSOMS versions 4.0 to 6.0.2 are affected by CVE-2019-19090.
The severity rating of CVE-2019-19090 is low, with a severity value of 3.5.
To fix the CVE-2019-19090 vulnerability in ABB eSOMS, it is recommended to set the Secure Flag in the HTTP response header to ensure encryption of connections and protect the cookie information.