SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5477

An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Application Version 8.0 and prior, and…

MEDIUM 5.8EPSS 1.23%

Does this matter?

Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.

Description

An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Application Version 8.0 and prior, and netCADOPS Web Application Version 8.1 and prior. A vulnerability exists in the password entry section of netCADOPS Web Application that may expose critical database information.

CVSS 3.0
5.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS
1.23% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
abb/netcadops
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.