IM
IronMonkey Threat Research

CVE-2019-19002 MEDIUM

Published: 2020-04-02 | Last Modified: 2024-11-21 | Status: Modified

Description

For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.

Additional Descriptions (1)

Para ABB eSOMS versiones 4.0 hasta 6.0.2, el encabezado de respuesta HTTP X-XSS-Protection no está configurado en las respuestas del servidor web. Para navegadores web más antiguos no compatibles con la Política de Seguridad de Contenido, esto podría aumentar el riesgo de ataques de tipo Cross Site Scripting.

CVSS Metrics

Base Score: 5.4 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.3

Impact Score: 2.7

Base Score: 3.5 (LOW)

AV:N/AC:M/Au:S/C:N/I:P/A:N

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationSINGLE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 6.8

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-16
en CWE-79
[email protected] Primary
en CWE-79

Affected Products

Vendor Product Version Update Type
hitachienergy esoms * <built-in method update of dict object at 0x72a9b0b5c080> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hitachienergy:esoms:*:*:*:*:*:*:*:*
Notification
Message here