First published: Fri Apr 06 2018(Updated: )
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
InduSoft Web Studio | <=8.1 | |
Industrial-software Intouch Machine Edition 2017 | <=8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8840 has a severity rating that indicates it may allow for remote code execution.
To fix CVE-2018-8840, upgrade to versions later than 8.1 for InduSoft Web Studio and InTouch Machine Edition 2017.
CVE-2018-8840 affects InduSoft Web Studio v8.1 and prior, as well as InTouch Machine Edition 2017 v8.1 and prior.
CVE-2018-8840 can be exploited through sending a crafted packet during actions like read and write related to tags, alarms, or events.
Organizations using InduSoft Web Studio or InTouch Machine Edition versions susceptible to CVE-2018-8840 should be concerned due to the potential for remote code execution.