CVE-2019-19000

MEDIUM

ABB eSOMS 4.0-6.0.3 - Sensitive Information Exposure via Improper Cache-Control Headers

Title source: llm
STIX 2.1

Description

For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.

Scores

CVSS v3 6.5
EPSS 0.0105
EPSS Percentile 60.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-16 CWE-200 CWE-202
Status published
Products (1)
hitachienergy/esoms 4.0 - 6.0.3
Published Apr 02, 2020
Tracked Since Feb 18, 2026