CVE-2018-10620Stack-based Buffer Overflow in Software LLC Indusoft WEB Studio

Severity
9.8CRITICALNVD
EPSS
5.0%
top 10.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 13

Description

AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-92qr-7f7r-87vw: AVEVA InduSoft Web Studio v82022-05-13
CVEList
CVE-2018-10620: AVEVA InduSoft Web Studio v82018-07-19
CVE-2018-10620 — Stack-based Buffer Overflow | cvebase