CVE-2019-6543: Critical severity AVEVA InduSoft Web Studio vulnerability
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6543?
CVE-2019-6543 is a vulnerability in AVEVA Software LLC InduSoft Web Studio and InTouch Edge HMI that allows code execution under program runtime privileges, potentially compromising the machine.
How severe is CVE-2019-6543?
CVE-2019-6543 has a severity rating of 9.8, which is considered critical.
What is the affected software for CVE-2019-6543?
The affected software for CVE-2019-6543 includes AVEVA InduSoft Web Studio versions 6.1-sp5, 6.1-sp6_p3, 7.1 to 7.1-sp3_p9, 8.0 to 8.0-sp2_p1, and 8.1 to 8.1-sp2, as well as Aveva Intouch Machine Edition 2014 R2.
How can I fix CVE-2019-6543?
To mitigate CVE-2019-6543, it is recommended to upgrade to AVEVA InduSoft Web Studio version 8.1 SP3 or InTouch Edge HMI version 2017 Update and apply any necessary security patches.
Where can I find more information about CVE-2019-6543?
You can find more information about CVE-2019-6543 at the following references: [1] https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01, [2] https://www.exploit-db.com/exploits/46342/, [3] https://www.tenable.com/security/research/tra-2019-04.