CVE-2019-6545

HIGH

AVEVA Software, LLC InduSoft Web Studio <8.1 SP3 & InTouch Edge HMI...

Title source: llm
STIX 2.1

Description

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.

Exploits (1)

exploitdb WORKING POC
by Jacob Baines · pythonremotemultiple
https://www.exploit-db.com/exploits/46342

Scores

CVSS v3 7.5
EPSS 0.1873
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-99
Status published
Products (5)
aveva/indusoft_web_studio 6.1 sp5 (2 CPE variants)
aveva/indusoft_web_studio 7.1 (13 CPE variants)
aveva/indusoft_web_studio 8.0 (8 CPE variants)
aveva/indusoft_web_studio 8.1 (5 CPE variants)
aveva/intouch_machine_edition_2014 r2
Published Feb 13, 2019
Tracked Since Feb 18, 2026