CVE-2019-6543
critical-risk
Published 2019-02-13
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
Do I need to act?
!
32.5% chance of exploitation in next 30 days
EPSS score — higher than 68% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (20)
Affected Vendors
References (6)
Third Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01
Third Party Advisory
https://www.tenable.com/security/research/tra-2019-04
Third Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01
Third Party Advisory
https://www.tenable.com/security/research/tra-2019-04
70
/ 100
critical-risk
Severity
32/34 · Critical
Exploitability
16/34 · Moderate
Exposure
22/34 · High