Vulnerability Description
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Esoms | 6.0.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105169Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-240-04Third Party AdvisoryUS Government Resource
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK107046A5821&LanguageMitigationVendor Advisory
- http://www.securityfocus.com/bid/105169Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-240-04Third Party AdvisoryUS Government Resource
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK107046A5821&LanguageMitigationVendor Advisory
FAQ
What is CVE-2018-14805?
CVE-2018-14805 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both condi...
How severe is CVE-2018-14805?
CVE-2018-14805 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-14805?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachienergy Esoms.