Learn about CVE-2019-19090 affecting ABB eSOMS versions 4.0 to 6.0.2. Understand the impact, technical details, and mitigation steps for this vulnerability.
ABB eSOMS versions 4.0 to 6.0.2 are vulnerable due to the absence of the Secure Flag in the HTTP response header, potentially exposing cookie information to eavesdropping.
Understanding CVE-2019-19090
This CVE involves the lack of the Secure Flag in the HTTP response header of ABB eSOMS versions 4.0 to 6.0.2, leading to a security vulnerability.
What is CVE-2019-19090?
The CVE-2019-19090 vulnerability pertains to ABB eSOMS versions 4.0 to 6.0.2, where the Secure Flag is not set in the HTTP response header, allowing unencrypted connections to potentially access cookie information, making it susceptible to eavesdropping.
The Impact of CVE-2019-19090
Technical Details of CVE-2019-19090
This section provides detailed technical information about the CVE-2019-19090 vulnerability.
Vulnerability Description
The vulnerability arises from the absence of the Secure Flag in the HTTP response header of ABB eSOMS versions 4.0 to 6.0.2, allowing potential access to cookie information over unencrypted connections.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by intercepting unencrypted connections to access sensitive cookie information, posing a risk of eavesdropping.
Mitigation and Prevention
To address CVE-2019-19090, follow these mitigation strategies:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates