peter bassill · operator
$ cve CVE-2019-6543 JSON

CVE-2019-6543 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 17.3% (pctl 97)

Patch early

A public exploit exists.

Description

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS17.29% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2019-02-13
Last modified2026-06-17

Affected (2)

VendorProduct
avevaindusoft web studio
avevaintouch machine edition 2014

Public exploits

SourceTitleDate
exploit-dbIndusoft Web Studio 8.1 SP2 - Remote Code Execution2019-02-11

References

→ the Explorer  ·  watch your stack  ·  NVD