漏洞信息详情
AVEVA Group plc InduSoft Web Studio和InTouch Edge HMI 访问控制错误漏洞
漏洞简介
AVEVA Group plc InduSoft Web Studio是英国AVEVA Group plc公司的一套工业组态软件。
AVEVA Group plc InduSoft Web Studio 8.1 SP3之前版本和InTouch Edge HMI 2017 Update之前版本中存在安全漏洞。攻击者可利用该漏洞执行代码。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec133.pdf?hsLang=en
参考网址
来源:MISC
链接:https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01
来源:www.tenable.com
链接:https://www.tenable.com/security/research/tra-2019-04
来源:EXPLOIT-DB
链接:https://www.exploit-db.com/exploits/46342/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75070
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-6543
来源:ics-cert.us-cert.gov
链接:https://ics-cert.us-cert.gov/advisories/ICSA-19-036-01
受影响实体
暂无
补丁
- AVEVA Group plc InduSoft Web Studio和InTouch Edge HMI 安全漏洞的修复措施<!--2019-2-12-->
还没有评论,来说两句吧...