ZeroHour

CVE-2019-19090

CVSS 3.1
3.5 low
EPSS
<1%p42
Published
()
Modified
Description

For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.

Vendors
hitachienergy
Products
esoms
Weakness
CWE-16, CWE-311
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.