First published: Tue Feb 05 2019(Updated: )
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA InduSoft Web Studio | =6.1-sp5 | |
AVEVA InduSoft Web Studio | =6.1-sp6_p3 | |
AVEVA InduSoft Web Studio | =7.1 | |
AVEVA InduSoft Web Studio | =7.1-sp1 | |
AVEVA InduSoft Web Studio | =7.1-sp2 | |
AVEVA InduSoft Web Studio | =7.1-sp3 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p1 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p2 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p3 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p4 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p5 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p6 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p7 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p8 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p9 | |
AVEVA InduSoft Web Studio | =8.0 | |
AVEVA InduSoft Web Studio | =8.0-p1 | |
AVEVA InduSoft Web Studio | =8.0-p2 | |
AVEVA InduSoft Web Studio | =8.0-p3 | |
AVEVA InduSoft Web Studio | =8.0-sp1 | |
AVEVA InduSoft Web Studio | =8.0-sp1_p1 | |
AVEVA InduSoft Web Studio | =8.0-sp2 | |
AVEVA InduSoft Web Studio | =8.0-sp2_p1 | |
AVEVA InduSoft Web Studio | =8.1 | |
AVEVA InduSoft Web Studio | =8.1-p1 | |
AVEVA InduSoft Web Studio | =8.1-sp1 | |
AVEVA InduSoft Web Studio | =8.1-sp1_p1 | |
AVEVA InduSoft Web Studio | =8.1-sp2 | |
Aveva Intouch Machine Edition 2014 | =r2 | |
=6.1-sp5 | ||
=6.1-sp6_p3 | ||
=7.1 | ||
=7.1-sp1 | ||
=7.1-sp2 | ||
=7.1-sp3 | ||
=7.1-sp3_p1 | ||
=7.1-sp3_p2 | ||
=7.1-sp3_p3 | ||
=7.1-sp3_p4 | ||
=7.1-sp3_p5 | ||
=7.1-sp3_p6 | ||
=7.1-sp3_p7 | ||
=7.1-sp3_p8 | ||
=7.1-sp3_p9 | ||
=8.0 | ||
=8.0-p1 | ||
=8.0-p2 | ||
=8.0-p3 | ||
=8.0-sp1 | ||
=8.0-sp1_p1 | ||
=8.0-sp2 | ||
=8.0-sp2_p1 | ||
=8.1 | ||
=8.1-p1 | ||
=8.1-sp1 | ||
=8.1-sp1_p1 | ||
=8.1-sp2 | ||
=r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6543 is a vulnerability in AVEVA Software LLC InduSoft Web Studio and InTouch Edge HMI that allows code execution under program runtime privileges, potentially compromising the machine.
CVE-2019-6543 has a severity rating of 9.8, which is considered critical.
The affected software for CVE-2019-6543 includes AVEVA InduSoft Web Studio versions 6.1-sp5, 6.1-sp6_p3, 7.1 to 7.1-sp3_p9, 8.0 to 8.0-sp2_p1, and 8.1 to 8.1-sp2, as well as Aveva Intouch Machine Edition 2014 R2.
To mitigate CVE-2019-6543, it is recommended to upgrade to AVEVA InduSoft Web Studio version 8.1 SP3 or InTouch Edge HMI version 2017 Update and apply any necessary security patches.
You can find more information about CVE-2019-6543 at the following references: [1] https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01, [2] https://www.exploit-db.com/exploits/46342/, [3] https://www.tenable.com/security/research/tra-2019-04.