PT-2018-1292 · Indusoft+1 · Indusoft Web Studio+1
Published
2018-04-06
·
Updated
2019-10-09
·
CVE-2018-8840
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InduSoft Web Studio versions 8.1 and prior
InTouch Machine Edition 2017 versions 8.1 and prior
Description
A remote attacker could send a carefully crafted packet during a tag, alarm, or event related action, such as read and write, which may allow remote code execution. The issue is caused by a stack-based buffer overflow. Exploitation of the issue may allow a remote attacker to execute arbitrary code using specially crafted packets.
Recommendations
For InduSoft Web Studio versions 8.1 and prior, consider disabling tag, alarm, or event related actions until a patch is available.
For InTouch Machine Edition 2017 versions 8.1 and prior, restrict access to the system during read and write actions to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intouch Machine Edition 2017
Indusoft Web Studio