VulnerabilityModified
CVE-2019-6543
Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
CRITICAL 9.8EPSS 17.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 17.29% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- aveva/indusoft web studio · aveva/intouch machine edition 2014
- Source
- ics-cert@hq.dhs.gov
References
- https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/46342/Exploit, Third Party Advisory, VDB Entry
- https://www.tenable.com/security/research/tra-2019-04Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/46342/Exploit, Third Party Advisory, VDB Entry
- https://www.tenable.com/security/research/tra-2019-04Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.