CVE-2018-10628
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.
Published:Jul 24, 2018
Last Modified:Nov 21, 2024
EPS:Jul 24, 2018
EPSS Score:0.05612
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Aveva
Product
Intouch 2014
Aveva
Intouch 2014
Vendor
Aveva
Product
Intouch 2017
Aveva
Intouch 2017
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
