CVE-2019-6545
Indusoft Web Studio 8.1 SP2 - Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
InduSoft Web Studio, en versiones anteriores a la 8.1 SP3 e InTouch Edge HMI (anteriormente conocido como InTouch Machine Edition), en versiones anteriores a la 2017 Update, de AVEVA Software, LLC. Un usuario no autenticado remoto podría emplear un archivo de configuración de conexión a la base de datos especialmente manipulado para ejecutar un proceso arbitrario en la máquina del servidor.
Indusoft Web Studio version 8.1 SP2 suffers from a remote code execution vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-22 CVE Reserved
- 2019-02-11 CVE Published
- 2024-06-28 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-99: Improper Control of Resource Identifiers ('Resource Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01 | Mitigation | |
https://www.tenable.com/security/research/tra-2019-04 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/46342 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 6.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "6.1" | sp5 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 6.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "6.1" | sp6_p3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | - |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p4 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p5 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p6 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p7 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p8 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 7.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "7.1" | sp3_p9 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | - |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | p2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | p3 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp1_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.0 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.0" | sp2_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | - |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | sp1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | sp1_p1 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Indusoft Web Studio Search vendor "Aveva" for product "Indusoft Web Studio" | 8.1 Search vendor "Aveva" for product "Indusoft Web Studio" and version "8.1" | sp2 |
Affected
| ||||||
Aveva Search vendor "Aveva" | Intouch Machine Edition 2014 Search vendor "Aveva" for product "Intouch Machine Edition 2014" | r2 Search vendor "Aveva" for product "Intouch Machine Edition 2014" and version "r2" | - |
Affected
|