7.5

CVE-2019-6545

Exploit
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ Indusoft Web Studio Version 6.1 Update sp5
Aveva ≫ Indusoft Web Studio Version 6.1 Update sp6_p3
Aveva ≫ Indusoft Web Studio Version 7.1
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp1
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp2
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p1
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p2
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p3
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p4
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p5
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p6
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p7
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p8
Aveva ≫ Indusoft Web Studio Version 7.1 Update sp3_p9
Aveva ≫ Indusoft Web Studio Version 8.0
Aveva ≫ Indusoft Web Studio Version 8.0 Update p1
Aveva ≫ Indusoft Web Studio Version 8.0 Update p2
Aveva ≫ Indusoft Web Studio Version 8.0 Update p3
Aveva ≫ Indusoft Web Studio Version 8.0 Update sp1
Aveva ≫ Indusoft Web Studio Version 8.0 Update sp1_p1
Aveva ≫ Indusoft Web Studio Version 8.0 Update sp2
Aveva ≫ Indusoft Web Studio Version 8.0 Update sp2_p1
Aveva ≫ Indusoft Web Studio Version 8.1
Aveva ≫ Indusoft Web Studio Version 8.1 Update p1
Aveva ≫ Indusoft Web Studio Version 8.1 Update sp1
Aveva ≫ Indusoft Web Studio Version 8.1 Update sp1_p1
Aveva ≫ Indusoft Web Studio Version 8.1 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.86% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-99 Improper Control of Resource Identifiers ('Resource Injection')

The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.

https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01
Third Party Advisory
US Government Resource
Mitigation
https://www.exploit-db.com/exploits/46342/
Third Party Advisory
Exploit
VDB Entry
https://www.tenable.com/security/research/tra-2019-04
Third Party Advisory