Vulnerabilities > Hitachienergy

DATE CVE VULNERABILITY TITLE RISK
2020-04-02 CVE-2019-19001 Improper Restriction of Rendered UI Layers or Frames vulnerability in Hitachienergy Esoms 4.0/6.0/6.0.2
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response.
network
low complexity
hitachienergy CWE-1021
6.5
2020-04-02 CVE-2019-19000 Information Exposure vulnerability in Hitachienergy Esoms
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response.
network
low complexity
hitachienergy CWE-200
6.5
2020-02-17 CVE-2019-18998 Authorization Bypass Through User-Controlled Key vulnerability in Hitachienergy Asset Suite 9.0.0/9.5.0/9.6.0
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects.
network
low complexity
hitachienergy CWE-639
7.1
2019-11-27 CVE-2019-18253 Path Traversal vulnerability in Hitachienergy Relion 670 Firmware
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.
network
low complexity
hitachienergy CWE-22
critical
10.0
2019-11-27 CVE-2019-18247 Improper Input Validation vulnerability in Hitachienergy Relion 650 Firmware and Relion 670 Firmware
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service.
network
low complexity
hitachienergy CWE-20
7.5
2019-01-16 CVE-2018-20720 Improper Input Validation vulnerability in Hitachienergy Relion 630 Firmware 1.1.0/1.2.0/1.3.0
ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message.
network
low complexity
hitachienergy CWE-20
7.5
2018-08-29 CVE-2018-14805 Improper Authentication vulnerability in Hitachienergy Esoms 6.0.2
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present.
network
low complexity
hitachienergy CWE-287
critical
9.8
2018-02-21 CVE-2018-1168 Incorrect Permission Assignment for Critical Resource vulnerability in Hitachienergy Sys600 Firmware
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3.
local
low complexity
hitachienergy CWE-732
7.8
2017-12-20 CVE-2017-16731 Insufficiently Protected Credentials vulnerability in Hitachienergy Ellipse 8.3.0/8.9.0
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select).
low complexity
hitachienergy CWE-522
8.8
2017-11-06 CVE-2017-14025 Improper Input Validation vulnerability in Hitachienergy Fox515T Firmware 1.0
An Improper Input Validation issue was discovered in ABB FOX515T release 1.0.
local
low complexity
hitachienergy CWE-20
5.5