ABB eSOMS X-XSS-Protection not enabled
CVE-2019-19002

6.3MEDIUM

Key Information:

Vendor

Abb

Status
Vendor
CVE Published:
2 April 2020

What is CVE-2019-19002?

For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.

Affected Version(s)

eSOMS 4.0 to 6.0.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.