Unrated severityNVD Advisory· Published Jul 24, 2018· Updated Sep 16, 2024
CVE-2018-10628
CVE-2018-10628
Description
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.
Affected products
1- Range: 2014 R2 SP1 and prior
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/104864mitrevdb-entryx_refsource_BID
- ics-cert.us-cert.gov/advisories/ICSA-18-200-02mitrex_refsource_MISC
- sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec127%28003%29.pdfmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.