CVE-2019-6525

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
11/04/2019
Last modified:
16/10/2020

Description

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aveva:wonderware_system_platform:*:*:*:*:*:*:*:* 2017 (excluding)
cpe:2.3:a:aveva:wonderware_system_platform:2017:-:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:2017:update_1:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:2017:update_2:*:*:*:*:*:*