CVE-2018-5477
An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Application Version 8.0 and prior, and…
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Application Version 8.0 and prior, and netCADOPS Web Application Version 8.1 and prior. A vulnerability exists in the password entry section of netCADOPS Web Application that may expose critical database information.
- CVSS 3.0
- 5.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- abb/netcadops
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/103089Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-051-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/103089Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-051-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.