CVE-2018-10628
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
24/07/2018
Last modified:
07/11/2023
Description
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:aveva:intouch_2014:r2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aveva:intouch_2014:r2:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:aveva:intouch_2017:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aveva:intouch_2017:-:update_1:*:*:*:*:*:* | ||
| cpe:2.3:a:aveva:intouch_2017:-:update_2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



