CVE-2019-19092

LOW

Hitachi Energy eSOMS 4.0-6.0.3 - Viewstate Integrity Bypass via Missing Message Authentication Code

Title source: llm
STIX 2.1

Description

ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.

Scores

CVSS v3 3.5
EPSS 0.0083
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-16 CWE-306
Status published
Products (1)
hitachienergy/esoms 4.0 - 6.0.3
Published Apr 02, 2020
Tracked Since Feb 18, 2026