PT-2018-1292 · Indusoft+1 · Indusoft Web Studio+1

Published

2018-04-06

·

Updated

2019-10-09

·

CVE-2018-8840

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InduSoft Web Studio versions 8.1 and prior InTouch Machine Edition 2017 versions 8.1 and prior
Description A remote attacker could send a carefully crafted packet during a tag, alarm, or event related action, such as read and write, which may allow remote code execution. The issue is caused by a stack-based buffer overflow. Exploitation of the issue may allow a remote attacker to execute arbitrary code using specially crafted packets.
Recommendations For InduSoft Web Studio versions 8.1 and prior, consider disabling tag, alarm, or event related actions until a patch is available. For InTouch Machine Edition 2017 versions 8.1 and prior, restrict access to the system during read and write actions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00788
CVE-2018-8840

Affected Products

Intouch Machine Edition 2017
Indusoft Web Studio