CVE-2018-17914: Critical severity aveva edge vulnerability
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
CVE-2018-17914
What is the severity level of CVE-2018-17914?
CVE-2018-17914 has a severity level of critical.
Which software versions are affected by CVE-2018-17914?
CVE-2018-17914 affects InduSoft Web Studio versions prior to 8.1 SP2 and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
How can an attacker exploit CVE-2018-17914?
CVE-2018-17914 could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI.
Are there any references related to CVE-2018-17914?
Yes, you can find more information about CVE-2018-17914 at the following references: [1] https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01, [2] https://www.tenable.com/security/research/tra-2018-34