CVE-2019-6543
CRITICALAveva Indusoft Web Studio - Missing Authentication
Title source: ruleDescription
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
Exploits (1)
exploitdb
WORKING POC
by Jacob Baines · pythonremotemultiple
https://www.exploit-db.com/exploits/46342
Scores
CVSS v3
9.8
EPSS
0.3247
EPSS Percentile
96.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (5)
aveva/indusoft_web_studio
6.1 sp5 (2 CPE variants)
aveva/indusoft_web_studio
7.1 (13 CPE variants)
aveva/indusoft_web_studio
8.0 (8 CPE variants)
aveva/indusoft_web_studio
8.1 (5 CPE variants)
aveva/intouch_machine_edition_2014
r2
Published
Feb 13, 2019
Tracked Since
Feb 18, 2026