AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NAveva Indusoft Web Studio
APPAveva6.17.18.08.1Aveva Intouch Machine Edition 2014
APPAvevar2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2019-6543CRITICAL9.8PL ✓same product
Wykonanie kodu bez uwierzytelnienia w AVEVA InduSoft Web Studio i InTouch Edge HMI
CVE-2018-17914CRITICAL9.8PL ✓same product
RCE bez uwierzytelnienia w Aveva InduSoft Web Studio i InTouch Edge HMI
CVE-2018-17916CRITICAL9.8PL ✓same product
Stack-based buffer overflow i RCE w Aveva InduSoft Web Studio i InTouch Edge HMI
CVE-2018-10620CRITICAL9.8PL ✓same product
Stack-based buffer overflow w AVEVA InduSoft Web Studio i InTouch Machine Edition
CVE-2025-61937CRITICAL10.0PL ✓same vendor
RCE z uprawnieniami systemowymi w Aveva Process Optimization