Home Embedded Vulns General Vulns

CVE-2019-19089

MEDIUM 6.1

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date April 2, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.

Potentially Affected Vendors