CVE-2018-10628 is a critical buffer overflow vulnerability affecting AVEVA InTouch 2014 R2 SP1 and prior, and all InTouch 2017 versions. An unauthenticated attacker can exploit this by sending a specially crafted packet to a system configured with a non-dot floating point separator. This allows for remote code execution with the privileges of the InTouch View process, posing a severe risk to affected industrial control systems. Despite its critical CVSS score of 9.8, there is no public exploit code available, nor is it listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting limited public awareness or active threat intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r2CPE matchmatch criteria | cpe:2.3:a:aveva:intouch_2014:r2:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:a:aveva:intouch_2014:r2:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:aveva:intouch_2017:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:aveva:intouch_2017:-:update_1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:aveva:intouch_2017:-:update_2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.