peter bassill · operator
$ cve CVE-2019-6545 JSON

CVE-2019-6545 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 13.9% (pctl 96)

Patch early

A public exploit exists.

Description

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS13.86% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-99
On CISA KEVno
Public exploityes
Published2019-02-13
Last modified2026-06-17

Affected (2)

VendorProduct
avevaindusoft web studio
avevaintouch machine edition 2014

Public exploits

SourceTitleDate
exploit-dbIndusoft Web Studio 8.1 SP2 - Remote Code Execution2019-02-11

References

→ the Explorer  ·  watch your stack  ·  NVD