Vulnerability Details CVE-2019-19001
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.7%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2019-19001
-
cpe:2.3:a:hitachienergy:esoms:4.0
-
cpe:2.3:a:hitachienergy:esoms:6.0
-
cpe:2.3:a:hitachienergy:esoms:6.0.2