CVE-2019-6545
PoC —CVSS 3.1
7.5 high
EPSS
14%p96
Published
()
Modified
Description
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
- Vendors
- aveva
- Products
- indusoft web studio, intouch machine edition 2014
- Weakness
- CWE-99
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.