← back
CVE-2019-19090

ABB eSOMS: Secure Flag not set

CVSS 3.5 LOWEPSS 0.5%CWE-16
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Affected products
ABB · eSOMS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →