CVE-2019-19089: Hitachienergy Esoms

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.

Affected products

Published 2020-04-02. Last modified 2026-06-17.