CVE-2019-6545
HIGHAVEVA Software, LLC InduSoft Web Studio <8.1 SP3 & InTouch Edge HMI...
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-6545. PoCs published by Jacob Baines.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated remote code execution vulnerability in Indusoft Web Studio by crafting a malicious DB.xdc file and leveraging SMB server interaction to trigger arbitrary command execution (e.g., calc.exe). The exploit uses a custom protocol to send commands to the target and validates the response.
Description
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
Exploits (1)
This exploit demonstrates an unauthenticated remote code execution vulnerability in Indusoft Web Studio by crafting a malicious DB.xdc file and leveraging SMB server interaction to trigger arbitrary command execution (e.g., calc.exe). The exploit uses a custom protocol to send commands to the target and validates the response.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N