Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)14%—Aveva Indusoft WEB StudioAveva Intouch Machine Edition 201413/2/201917/6/2026
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
ModificadaCrítica (9.8)17%—Aveva Indusoft WEB StudioAveva Intouch Machine Edition 201413/2/201917/6/2026
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
ModificadaCrítica (9.8)3.7%—Aveva Indusoft WEB StudioAveva EdgeAveva Intouch Machine Edition 20142/11/201817/6/2026
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with…
ModificadaCrítica (9.8)4.6%—Aveva Indusoft WEB StudioAveva EdgeAveva Intouch Machine Edition 20142/11/201817/6/2026
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine…
ModificadaCrítica (9.8)4.2%—Aveva Indusoft WEB StudioAveva Intouch Machine 201719/7/201817/6/2026
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed.
ModificadaCrítica (9.8)5.8%—Schneider-electric Wonderware Indusoft WEB StudioSchneider-electric Wonderware Intouch13/11/201717/6/2026
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution with high…
ModificadaCrítica (9.8)5.1%—Schneider-electric Wonderware Indusoft WEB StudioSchneider-electric Wonderware Intouch3/10/201717/6/2026
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing…
ModificadaAlta (7.8)0.43%—Schneider-electric Wonderware Indusoft WEB Studio19/5/201717/6/2026
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This…