CVE-2019-19002

CVSS v3 Score
5.4
Medium
CVSS v2 Score
3.5
Low

Vulnerability Description

For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.

CVSS:5.5(Medium)

Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.

CWE-162018
CVSS:5.5(Medium)

Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-162023
CVSS:5.5(Medium)

Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-162024
CVSS:5.5(Medium)

Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.

CWE-162024
CVSS:5.3(Medium)

A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use thi...

CWE-162018
CVSS:5.3(Medium)

A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information. The vulnerability is due to...

CWE-162019