CVE-2019-6543

CRITICAL

Aveva Indusoft Web Studio - Missing Authentication

Title source: rule

Description

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.

Exploits (1)

exploitdb WORKING POC
by Jacob Baines · pythonremotemultiple
https://www.exploit-db.com/exploits/46342

Scores

CVSS v3 9.8
EPSS 0.3247
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (5)
aveva/indusoft_web_studio 6.1 sp5 (2 CPE variants)
aveva/indusoft_web_studio 7.1 (13 CPE variants)
aveva/indusoft_web_studio 8.0 (8 CPE variants)
aveva/indusoft_web_studio 8.1 (5 CPE variants)
aveva/intouch_machine_edition_2014 r2
Published Feb 13, 2019
Tracked Since Feb 18, 2026