CVE-2018-14805
Summary
| CVE | CVE-2018-14805 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-29 16:29:00 UTC |
| Updated | 2023-05-16 20:21:00 UTC |
| Description | ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ABB eSOMS CVE-2018-14805 Authentication Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| ABB eSOMS (Update A) | CISA | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| ABB Security Advisory 2018030 eSOMS LDAP Integration | CONFIRM | search.abb.com | Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.