PT-2018-3326 · Abb · Abb Esoms
CVE-2018-14805
·
Publicado
2018-08-10
·
Atualizado
2023-05-16
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ABB eSOMS version 6.0.2
Description:
The issue is related to the incorrect operation of the authentication mechanism in ABB eSOMS. This can allow a remote attacker to gain unauthorized access to the system if LDAP is configured for anonymous authentication and specific key values are present in the eSOMS web.config file. Both conditions must be met for the issue to be exploited.
Recommendations:
For ABB eSOMS version 6.0.2, consider disabling anonymous LDAP authentication and review the eSOMS web.config file to ensure that it does not contain the specific key values that can be exploited. Restrict access to the system until a proper fix can be applied.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Abb Esoms