7.5
CVSSv3

CVE-2019-6545

Published: 13/02/2019 Updated: 31/01/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aveva indusoft web studio 8.1

aveva indusoft web studio 8.0

aveva indusoft web studio 7.1

aveva indusoft web studio 6.1

aveva intouch machine edition 2014 r2

Exploits

Indusoft Web Studio version 81 SP2 suffers from a remote code execution vulnerability ...