First published: Wed Feb 13 2019(Updated: )
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA InduSoft Web Studio | =6.1-sp5 | |
AVEVA InduSoft Web Studio | =6.1-sp6_p3 | |
AVEVA InduSoft Web Studio | =7.1 | |
AVEVA InduSoft Web Studio | =7.1-sp1 | |
AVEVA InduSoft Web Studio | =7.1-sp2 | |
AVEVA InduSoft Web Studio | =7.1-sp3 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p1 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p2 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p3 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p4 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p5 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p6 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p7 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p8 | |
AVEVA InduSoft Web Studio | =7.1-sp3_p9 | |
AVEVA InduSoft Web Studio | =8.0 | |
AVEVA InduSoft Web Studio | =8.0-p1 | |
AVEVA InduSoft Web Studio | =8.0-p2 | |
AVEVA InduSoft Web Studio | =8.0-p3 | |
AVEVA InduSoft Web Studio | =8.0-sp1 | |
AVEVA InduSoft Web Studio | =8.0-sp1_p1 | |
AVEVA InduSoft Web Studio | =8.0-sp2 | |
AVEVA InduSoft Web Studio | =8.0-sp2_p1 | |
AVEVA InduSoft Web Studio | =8.1 | |
AVEVA InduSoft Web Studio | =8.1-p1 | |
AVEVA InduSoft Web Studio | =8.1-sp1 | |
AVEVA InduSoft Web Studio | =8.1-sp1_p1 | |
AVEVA InduSoft Web Studio | =8.1-sp2 | |
Aveva Intouch Machine Edition 2014 | =r2 | |
=6.1-sp5 | ||
=6.1-sp6_p3 | ||
=7.1 | ||
=7.1-sp1 | ||
=7.1-sp2 | ||
=7.1-sp3 | ||
=7.1-sp3_p1 | ||
=7.1-sp3_p2 | ||
=7.1-sp3_p3 | ||
=7.1-sp3_p4 | ||
=7.1-sp3_p5 | ||
=7.1-sp3_p6 | ||
=7.1-sp3_p7 | ||
=7.1-sp3_p8 | ||
=7.1-sp3_p9 | ||
=8.0 | ||
=8.0-p1 | ||
=8.0-p2 | ||
=8.0-p3 | ||
=8.0-sp1 | ||
=8.0-sp1_p1 | ||
=8.0-sp2 | ||
=8.0-sp2_p1 | ||
=8.1 | ||
=8.1-p1 | ||
=8.1-sp1 | ||
=8.1-sp1_p1 | ||
=8.1-sp2 | ||
=r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6545 is high with a severity value of 7.5.
The affected software versions of CVE-2019-6545 are AVEVA InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update.
An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server.
Yes, there are known exploits for CVE-2019-6545. You can find more information at the provided references.
You can find more information about CVE-2019-6545 at the provided references.