CVE-2019-6525: High severity wonderware system platform vulnerability
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6525?
CVE-2019-6525 is a vulnerability in AVEVA Wonderware System Platform 2017 Update 2 and prior that allows a user with low privileges to obtain the credentials for an ArchestrA network user account.
How does CVE-2019-6525 impact AVEVA Wonderware System Platform?
CVE-2019-6525 can be exploited by a user with low privileges to obtain the credentials for the ArchestrA network user account used for authentication of system processes and inter-node communications in AVEVA Wonderware System Platform.
What is the severity of CVE-2019-6525?
CVE-2019-6525 has a severity score of 8.8 out of 10, indicating a high severity.
Which versions of AVEVA Wonderware System Platform are affected by CVE-2019-6525?
CVE-2019-6525 affects AVEVA Wonderware System Platform 2017, 2017-update_1, and 2017-update_2.
How can I fix CVE-2019-6525?
To fix CVE-2019-6525, it is recommended to upgrade to a version of AVEVA Wonderware System Platform that is not affected by the vulnerability.