10

CVE-2018-17914

Exploit

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AvevaIndusoft Web Studio Version6.1 Updatesp5
AvevaIndusoft Web Studio Version6.1 Updatesp6_p3
AvevaIndusoft Web Studio Version7.1
AvevaIndusoft Web Studio Version7.1 Updatesp1
AvevaIndusoft Web Studio Version7.1 Updatesp2
AvevaIndusoft Web Studio Version7.1 Updatesp3
AvevaIndusoft Web Studio Version7.1 Updatesp3_p1
AvevaIndusoft Web Studio Version7.1 Updatesp3_p2
AvevaIndusoft Web Studio Version7.1 Updatesp3_p3
AvevaIndusoft Web Studio Version7.1 Updatesp3_p4
AvevaIndusoft Web Studio Version7.1 Updatesp3_p5
AvevaIndusoft Web Studio Version7.1 Updatesp3_p6
AvevaIndusoft Web Studio Version7.1 Updatesp3_p7
AvevaIndusoft Web Studio Version7.1 Updatesp3_p8
AvevaIndusoft Web Studio Version7.1 Updatesp3_p9
AvevaIndusoft Web Studio Version8.0
AvevaIndusoft Web Studio Version8.0 Updatep1
AvevaIndusoft Web Studio Version8.0 Updatep2
AvevaIndusoft Web Studio Version8.0 Updatep3
AvevaIndusoft Web Studio Version8.0 Updatesp1
AvevaIndusoft Web Studio Version8.0 Updatesp1_p1
AvevaIndusoft Web Studio Version8.0 Updatesp2
AvevaIndusoft Web Studio Version8.0 Updatesp2_p1
AvevaIndusoft Web Studio Version8.1
AvevaIndusoft Web Studio Version8.1 Updatep1
AvevaIndusoft Web Studio Version8.1 Updatesp1
AvevaIndusoft Web Studio Version8.1 Updatesp1_p1
AvevaEdge Version8.1 Update-
AvevaEdge Version8.1 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.9% 0.878
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-258 Empty Password in Configuration File

Using an empty string as a password is insecure.