CVE-2019-6525

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aveva:wonderware_system_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:2017:-:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:2017:update_1:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:2017:update_2:*:*:*:*:*:*

History

21 Nov 2024, 04:46

Type Values Removed Values Added
References () https://ics-cert.us-cert.gov/advisories/ICSA-19-029-03 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-19-029-03 - Third Party Advisory, US Government Resource
References () https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec135.pdf - Vendor Advisory () https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec135.pdf - Vendor Advisory

Information

Published : 2019-04-11 21:29

Updated : 2024-11-21 04:46


NVD link : CVE-2019-6525

Mitre link : CVE-2019-6525

CVE.ORG link : CVE-2019-6525


JSON object : View

Products Affected

aveva

  • wonderware_system_platform
CWE
CWE-522

Insufficiently Protected Credentials

CWE-269

Improper Privilege Management