CVE-2018-17916
Last modified
CVE-2018-17916 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. EPSS estimates a 3.73% chance of exploitation in the next 30 days.
Description
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. If InduSoft Web Studio remote communication security was not enabled, or a password was left blank, a remote user could send a carefully crafted packet to invoke an arbitrary process, with potential for code to be executed. The code would be executed under the privileges of the InduSoft Web Studio or InTouch Edge HMI runtime and could lead to a compromise of the InduSoft Web Studio or InTouch Edge HMI server machine.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Aveva | Indusoft Web Studio | 6.1 | Sp5 |
| Aveva | Indusoft Web Studio | 7.1 | — |
| Aveva | Indusoft Web Studio | 8.0 | — |
| Aveva | Indusoft Web Studio | 8.1 | — |
| Aveva | Edge | 8.1 | — |
| Aveva | Intouch Machine Edition 2014 | r2 | — |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01Mitigation, Third Party Advisory, US Government Resource
- https://www.tenable.com/security/research/tra-2018-34Exploit, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01Mitigation, Third Party Advisory, US Government Resource
- https://www.tenable.com/security/research/tra-2018-34Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-17916?
How severe is CVE-2018-17916?
How do I fix CVE-2018-17916?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-17910WebAccess Versions 8.3.2 and prior. The application fails to…
- CVE-2018-17911LAquis SCADA Versions 4.1.0.3870 and prior has several stack…7.8
- CVE-2018-17912An XXE vulnerability exists in CASE Suite Versions 3.10 and …
- CVE-2018-17913A type confusion vulnerability exists when processing projec…
- CVE-2018-17914InduSoft Web Studio versions prior to 8.1 SP2, and InTouch E…9.8
- CVE-2018-17915All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye …
- CVE-2018-17917All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye …
- CVE-2018-17918Circontrol CirCarLife all versions prior to 4.3.1, authentic…
- CVE-2018-17919All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye …
- CVE-2018-1792IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9…8.8
- CVE-2018-17921SAGA1-L8B with any firmware versions prior to A0.10 are vuln…8.8
- CVE-2018-17922Circontrol CirCarLife all versions prior to 4.3.1, the PAP c…
Are you affected by CVE-2018-17916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
