CVE-2019-6543
Indusoft Web Studio 8.1 SP2 - Remote Code Execution
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
InduSoft Web Studio, en versiones anteriores a la 8.1 SP3 e InTouch Edge HMI (anteriormente conocido como InTouch Machine Edition), en versiones anteriores a la 2017 Update, de AVEVA Software, LLC. Se ejecuta código con los privilegios en tiempo de ejecución del programa, lo que podría conducir al compromiso de la máquina.
Indusoft Web Studio version 8.1 SP2 suffers from a remote code execution vulnerability.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-01-22 CVE Reserved
- 2019-02-11 CVE Published
- 2024-06-28 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01 | Third Party Advisory | |
https://www.tenable.com/security/research/tra-2019-04 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/46342 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 6.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "6.1" | sp5 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 6.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "6.1" | sp6_p3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | - |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p4 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p5 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p6 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p7 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p8 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p9 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | - |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | p2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | p3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp1_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp2_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | - |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | sp1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | sp1_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | sp2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Intouch Machine Edition 2014 Search vendor "Aveva" for product "Intouch Machine Edition 2014" | r2 Search vendor "Aveva" for product "Intouch Machine Edition 2014" and version "r2" | - |
Affected
|