CVE-2019-6545 is a critical remote code execution vulnerability affecting AVEVA InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated attacker can exploit this flaw by submitting a specially crafted database connection configuration file, leading to arbitrary process execution on the server. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, allowing for high integrity impact without user interaction. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, indicating a potential for exploitation, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1CPE matchmatch criteria | cpe:2.3:a:aveva:indusoft_web_studio:6.1:sp5:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:aveva:indusoft_web_studio:6.1:sp6_p3:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:aveva:indusoft_web_studio:7.1:*:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:aveva:indusoft_web_studio:7.1:sp1:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:aveva:indusoft_web_studio:7.1:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Indusoft Web Studio and InTouch Edge HMI Remote Code Execution
Feb 4, 2019Indusoft Web Studio and InTouch Edge HMI Remote Code Execution
Feb 4, 2019Indusoft Web Studio and InTouch Edge HMI Remote Code Execution
Feb 4, 2019