First published: Fri Nov 02 2018(Updated: )
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA InduSoft Web Studio | =6.1-sp5 | |
AVEVA InduSoft Web Studio | =6.1-sp6_p3 | |
AVEVA InduSoft Web Studio | =7.1 | |
AVEVA InduSoft Web Studio | =7.1-sp1 | |
AVEVA InduSoft Web Studio | =7.1-sp2 | |
AVEVA InduSoft Web Studio | =7.1-sp3 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p1 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p2 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p3 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p4 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p5 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p6 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p7 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p8 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p9 | |
AVEVA InduSoft Web Studio | =8.0 | |
AVEVA InduSoft Web Studio | =8.0-p1 | |
AVEVA InduSoft Web Studio | =8.0-p2 | |
AVEVA InduSoft Web Studio | =8.0-p3 | |
AVEVA InduSoft Web Studio | =8.0-sp1 | |
AVEVA InduSoft Web Studio | =8.0-sp1_p1 | |
AVEVA InduSoft Web Studio | =8.0-sp2 | |
AVEVA InduSoft Web Studio | =8.0-sp2_p1 | |
AVEVA InduSoft Web Studio | =8.1 | |
AVEVA InduSoft Web Studio | =8.1-p1 | |
AVEVA InduSoft Web Studio | =8.1-sp1 | |
AVEVA InduSoft Web Studio | =8.1-sp1_p1 | |
AVEVA Edge | =8.1 | |
AVEVA Edge | =8.1-sp1 | |
Aveva Intouch Machine Edition 2014 | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17914
CVE-2018-17914 has a severity level of critical.
CVE-2018-17914 affects InduSoft Web Studio versions prior to 8.1 SP2 and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
CVE-2018-17914 could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI.
Yes, you can find more information about CVE-2018-17914 at the following references: [1] https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01, [2] https://www.tenable.com/security/research/tra-2018-34