Learn about CVE-2019-19096 affecting ABB eSOMS versions 6.0 to 6.0.2. Discover the impact, technical details, and mitigation steps for this vulnerability.
In ABB eSOMS versions 6.0 to 6.0.2, the Redis data structure component stores credentials in plain text, posing a risk to confidentiality if unauthorized access occurs.
Understanding CVE-2019-19096
In this CVE, ABB eSOMS versions 6.0 to 6.0.2 are affected by a vulnerability related to storing credentials in clear text in the Redis data structure component.
What is CVE-2019-19096?
The vulnerability in ABB eSOMS versions 6.0 to 6.0.2 allows credentials to be stored in plain text within the Redis data structure, potentially compromising confidentiality if unauthorized access is gained.
The Impact of CVE-2019-19096
The vulnerability's impact is rated as MEDIUM with a base score of 6.1. It has a HIGH impact on confidentiality and LOW impact on integrity. The attack complexity is LOW, and it requires LOW privileges.
Technical Details of CVE-2019-19096
In-depth technical information about the vulnerability.
Vulnerability Description
The Redis data structure component in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in plain text, making them vulnerable to exposure if an unauthorized individual gains file system access.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability allows attackers with file system access to potentially retrieve credentials stored in clear text, compromising the confidentiality of sensitive information.
Mitigation and Prevention
Measures to address and prevent the CVE-2019-19096 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates