CVE-2018-14805

CRITICAL

ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both co...

Affects 1 product across 1 vendor.

BCS7.63
CVSS 3.09.8
EPSS4.8%
Percentile92th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2018. A critical vulnerability affects Hitachienergy systems (CVE-2018-14805). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2018-GLOBAL-219994-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2018-14805?
This vulnerability was disclosed in 2018. A critical vulnerability affects Hitachienergy systems (CVE-2018-14805). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2018-14805?
CVE-2018-14805 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 4.8%.
Is CVE-2018-14805 actively exploited?
No confirmed active exploitation of CVE-2018-14805 as of 2026-09-25.
How do I remediate CVE-2018-14805?
Priority: MEDIUM. Advisory: https://search.abb.com/library/Download.aspx?DocumentID=9AKK107046A5821&LanguageCode=en&DocumentPartId=&Action=Launch PSIRT: [email protected]
What systems are affected by CVE-2018-14805?
CVE-2018-14805 affects: Hitachienergy.
Vulnerability Details
CVE IDCVE-2018-14805
BSIDBS-2018-GLOBAL-219994-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2018-08-29
Last Modified2026-06-17
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Hitachienergy Esoms —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 2951 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash10e209b24070a890d196df95c8e88ea59aa37b6f48e7fe256458c5b5a767f3182b8e0bdbf16903aacb629296d17f060a39beee22f9ad4db4ab6540f6d88c0de2
Related CVEs affecting Hitachienergy
CVE-2019-18253 10.0 An attacker could use specially crafted paths in a specific request to read o... CVE-2024-2013 10.0 An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / ... CVE-2022-3927 9.8 The affected products store both public and private key that are used to sig... CVE-2019-5620 9.8 ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Mi... CVE-2021-40342 9.8 In the DES implementation, the affected product versions use a default key f...
View all Hitachienergy CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →