PT-2018-3326 · Abb · Abb Esoms

CVE-2018-14805

·

Published

2018-08-10

·

Updated

2023-05-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ABB eSOMS version 6.0.2
Description: The issue is related to the incorrect operation of the authentication mechanism in ABB eSOMS. This can allow a remote attacker to gain unauthorized access to the system if LDAP is configured for anonymous authentication and specific key values are present in the eSOMS web.config file. Both conditions must be met for the issue to be exploited.
Recommendations: For ABB eSOMS version 6.0.2, consider disabling anonymous LDAP authentication and review the eSOMS web.config file to ensure that it does not contain the specific key values that can be exploited. Restrict access to the system until a proper fix can be applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04818
CVE-2018-14805

Affected Products

Abb Esoms