CVE-2018-17914
This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.57% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-258
- Affected
- aveva/indusoft web studio · aveva/edge · aveva/intouch machine edition 2014
- Source
- ics-cert@hq.dhs.gov
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01Mitigation, Third Party Advisory, US Government Resource
- https://www.tenable.com/security/research/tra-2018-34Exploit, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01Mitigation, Third Party Advisory, US Government Resource
- https://www.tenable.com/security/research/tra-2018-34Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.