CVE-2018-8840

A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:indusoft:web_studio:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:industrial-software:intouch_machine_edition_2017:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000125/ - Third Party Advisory () http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000125/ - Third Party Advisory
References () http://www.securityfocus.com/bid/103949 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/103949 - Third Party Advisory, VDB Entry
References () https://ics-cert.us-cert.gov/advisories/ICSA-18-107-01 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-18-107-01 - Third Party Advisory, US Government Resource
References () https://www.tenable.com/security/research/tra-2018-07 - Third Party Advisory () https://www.tenable.com/security/research/tra-2018-07 - Third Party Advisory

Information

Published : 2018-04-18 20:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-8840

Mitre link : CVE-2018-8840

CVE.ORG link : CVE-2018-8840


JSON object : View

Products Affected

indusoft

  • web_studio

industrial-software

  • intouch_machine_edition_2017
CWE
CWE-121

Stack-based Buffer Overflow

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer