CVE-2018-17914 Vulnerability Details

  /     /     /  

CVE-2018-17914 Metadata Quick Info

CVE Published: 02/11/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: icscert | Vendor: unknown | Product: InduSoft Web Studio, and InTouch Edge HMI (formerly InTouch Machine Edition)
Status : PUBLISHED

CVE-2018-17914 Description

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-258
CWE Name: EMPTY PASSWORD IN CONFIGURATION FILE CWE-258
Source: unknown

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).