PT-2019-18157 · Aveva · Indusoft Web Studio+1

CVE-2019-6545

·

Publicado

2019-02-13

·

Atualizado

2023-01-31

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVEVA Software, LLC InduSoft Web Studio versions prior to 8.1 SP3 AVEVA Software, LLC InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 Update
Description An issue exists where an unauthenticated remote user could execute an arbitrary process on the server machine by using a specially crafted database connection configuration file.
Recommendations For AVEVA Software, LLC InduSoft Web Studio versions prior to 8.1 SP3, update to version 8.1 SP3 or later. For AVEVA Software, LLC InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 Update, update to version 2017 Update or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6545

Produtos afetados

Intouch Edge Hmi
Indusoft Web Studio