Filtered by vendor Hitachienergy
Subscribe
Total
70 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-19002 | 1 Hitachienergy | 1 Esoms | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting. | |||||
CVE-2019-19097 | 1 Hitachienergy | 1 Esoms | 2024-02-04 | 4.3 MEDIUM | 7.5 HIGH |
ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection. | |||||
CVE-2019-19000 | 1 Hitachienergy | 1 Esoms | 2024-02-04 | 6.4 MEDIUM | 6.5 MEDIUM |
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information. | |||||
CVE-2019-19089 | 1 Hitachienergy | 1 Esoms | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript. | |||||
CVE-2019-19090 | 1 Hitachienergy | 1 Esoms | 2024-02-04 | 3.5 LOW | 3.5 LOW |
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping. | |||||
CVE-2019-19091 | 1 Hitachienergy | 1 Esoms | 2024-02-04 | 4.0 MEDIUM | 4.3 MEDIUM |
For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack. | |||||
CVE-2019-19093 | 1 Hitachienergy | 1 Esoms | 2024-02-04 | 6.4 MEDIUM | 6.5 MEDIUM |
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords. | |||||
CVE-2019-18998 | 1 Hitachienergy | 1 Asset Suite | 2024-02-04 | 5.5 MEDIUM | 7.1 HIGH |
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly. | |||||
CVE-2019-18253 | 1 Hitachienergy | 2 Relion 670, Relion 670 Firmware | 2024-02-04 | 7.5 HIGH | 10.0 CRITICAL |
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory. | |||||
CVE-2019-18247 | 1 Hitachienergy | 4 Relion 650, Relion 650 Firmware, Relion 670 and 1 more | 2024-02-04 | 7.8 HIGH | 7.5 HIGH |
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service. |