CVE-2019-6545
HIGHAVEVA Software, LLC InduSoft Web Studio <8.1 SP3 & InTouch Edge HMI...
Title source: llmDescription
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
Exploits (1)
exploitdb
WORKING POC
by Jacob Baines · pythonremotemultiple
https://www.exploit-db.com/exploits/46342
Scores
CVSS v3
7.5
EPSS
0.1873
EPSS Percentile
95.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-99
Status
published
Products (5)
aveva/indusoft_web_studio
6.1 sp5 (2 CPE variants)
aveva/indusoft_web_studio
7.1 (13 CPE variants)
aveva/indusoft_web_studio
8.0 (8 CPE variants)
aveva/indusoft_web_studio
8.1 (5 CPE variants)
aveva/intouch_machine_edition_2014
r2
Published
Feb 13, 2019
Tracked Since
Feb 18, 2026