Vulnerability Description
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aveva | Indusoft Web Studio | 6.1 |
| Aveva | Edge | 8.1 |
| Aveva | Intouch Machine Edition 2014 | r2 |
Related Weaknesses (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01MitigationThird Party AdvisoryUS Government Resource
- https://www.tenable.com/security/research/tra-2018-34ExploitThird Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01MitigationThird Party AdvisoryUS Government Resource
- https://www.tenable.com/security/research/tra-2018-34ExploitThird Party Advisory
FAQ
What is CVE-2018-17914?
CVE-2018-17914 is a vulnerability with a CVSS score of 9.8 (CRITICAL). InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely ex...
How severe is CVE-2018-17914?
CVE-2018-17914 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-17914?
Check the references section above for vendor advisories and patch information. Affected products include: Aveva Indusoft Web Studio, Aveva Edge, Aveva Intouch Machine Edition 2014.