Vulnerability Description
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aveva | Indusoft Web Studio | 6.1 |
| Aveva | Intouch Machine Edition 2014 | r2 |
Related Weaknesses (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01Third Party AdvisoryUS Government Resource
- https://www.exploit-db.com/exploits/46342/ExploitThird Party AdvisoryVDB Entry
- https://www.tenable.com/security/research/tra-2019-04Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01Third Party AdvisoryUS Government Resource
- https://www.exploit-db.com/exploits/46342/ExploitThird Party AdvisoryVDB Entry
- https://www.tenable.com/security/research/tra-2019-04Third Party Advisory
FAQ
What is CVE-2019-6543?
CVE-2019-6543 is a vulnerability with a CVSS score of 9.8 (CRITICAL). AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privil...
How severe is CVE-2019-6543?
CVE-2019-6543 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-6543?
Check the references section above for vendor advisories and patch information. Affected products include: Aveva Indusoft Web Studio, Aveva Intouch Machine Edition 2014.