VYPR
Low severity3.5NVD Advisory· Published Apr 2, 2020· Updated Jun 17, 2026

CVE-2019-19090

CVE-2019-19090

Description

For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.

Affected products

3
  • cpe:2.3:a:hitachienergy:esoms:*:*:*:*:*:*:*:*
    Range: >=4.0,<=6.0.2
  • Abb/eSOMScpe-rescue2 versions
    4.0 to 6.0.2+ 1 more
    • (no CPE)range: 4.0 to 6.0.2
    • (no CPE)range: 4.0 to 6.0.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.