High severity7.5NVD Advisory· Published Feb 13, 2019· Updated Jun 17, 2026
CVE-2019-6545
CVE-2019-6545
Description
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: < 2017 Update
- Range: < 2017 Update
- Range: < 8.1 SP3
- ICS-CERT/AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Updatev5Range: AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/46342/nvdExploitThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-19-036-01nvdMitigationThird Party AdvisoryUS Government Resource
- www.tenable.com/security/research/tra-2019-04nvdThird Party Advisory
News mentions
0No linked articles in our index yet.