AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Indusoft_web_studio | Aveva | 6.1-sp5 (including) | 6.1-sp5 (including) |
Indusoft_web_studio | Aveva | 6.1-sp6_p3 (including) | 6.1-sp6_p3 (including) |
Indusoft_web_studio | Aveva | 7.1 (including) | 7.1 (including) |
Indusoft_web_studio | Aveva | 7.1-sp1 (including) | 7.1-sp1 (including) |
Indusoft_web_studio | Aveva | 7.1-sp2 (including) | 7.1-sp2 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3 (including) | 7.1-sp3 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p1 (including) | 7.1-sp3_p1 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p2 (including) | 7.1-sp3_p2 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p3 (including) | 7.1-sp3_p3 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p4 (including) | 7.1-sp3_p4 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p5 (including) | 7.1-sp3_p5 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p6 (including) | 7.1-sp3_p6 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p7 (including) | 7.1-sp3_p7 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p8 (including) | 7.1-sp3_p8 (including) |
Indusoft_web_studio | Aveva | 7.1-sp3_p9 (including) | 7.1-sp3_p9 (including) |
Indusoft_web_studio | Aveva | 8.0 (including) | 8.0 (including) |
Indusoft_web_studio | Aveva | 8.0-p1 (including) | 8.0-p1 (including) |
Indusoft_web_studio | Aveva | 8.0-p2 (including) | 8.0-p2 (including) |
Indusoft_web_studio | Aveva | 8.0-p3 (including) | 8.0-p3 (including) |
Indusoft_web_studio | Aveva | 8.0-sp1 (including) | 8.0-sp1 (including) |
Indusoft_web_studio | Aveva | 8.0-sp1_p1 (including) | 8.0-sp1_p1 (including) |
Indusoft_web_studio | Aveva | 8.0-sp2 (including) | 8.0-sp2 (including) |
Indusoft_web_studio | Aveva | 8.0-sp2_p1 (including) | 8.0-sp2_p1 (including) |
Indusoft_web_studio | Aveva | 8.1 (including) | 8.1 (including) |
Indusoft_web_studio | Aveva | 8.1-p1 (including) | 8.1-p1 (including) |
Indusoft_web_studio | Aveva | 8.1-sp1 (including) | 8.1-sp1 (including) |
Indusoft_web_studio | Aveva | 8.1-sp1_p1 (including) | 8.1-sp1_p1 (including) |
Indusoft_web_studio | Aveva | 8.1-sp2 (including) | 8.1-sp2 (including) |