The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.
References
Link | Resource |
---|---|
https://search.abb.com/library/Download.aspx?DocumentID=9AKK107492A9964&LanguageCode=en&DocumentPartId=&Action=Launch | Vendor Advisory |
Configurations
Information
Published : 2020-04-02 13:15
Updated : 2020-04-03 10:17
NVD link : CVE-2019-19096
Mitre link : CVE-2019-19096
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
abb
- esoms