← Back to home
ICSA-18-200-01  ·  Published 2018-07-19  ·  View on CISA ICS-CERT ↗

AVEVA InduSoft Web Studio and InTouch Machine Edition

CVSS 9.8 CRITICAL

Risk Summary

The listed products are vulnerable only if the TCP/IP Server Task is enabled. A remote attacker could send a carefully crafted packet during a tag, alarm, or event related action such as read and write, which may allow remote code execution.

CVEs (1)

Remediations

  • Users of InduSoft Web Studio v8.1 SP1 are affected and should apply InduSoft Web Studio Hotfix 81.1.00.08 as soon as possible. Users of InduSoft Web Studio v8.1 are also affected and should first upgrade to InduSoft Web Studio v8.1 SP1 and then apply the hotfix.
  • Users of InTouch Machine Edition 2017 v8.1 SP1 are affected and should apply InTouch Machine Edition Hotfix 81.1.00.08 as soon as possible. Users of InTouch Machine Edition 2017 v8.1 are also affected and should first upgrade to InTouch Machine Edition 2017 v8.1 SP1 and then apply the hotfix.
  • Software security updates:
  • Software security updates (login required):
  • To identify which version of InduSoft Web Studio or InTouch Machine Edition you have installed:
  • Windows Desktop or Server operating system: Navigate to Windows Programs and Features, locate the “InduSoft Web Studio” or “InTouch Machine Edition” entries to review the displayed installed version.
  • On a Windows Embedded operating system: navigate to the Bin folder in the installation location of InduSoft Web Studio or InTouch Machine Edition and open the file “CEView.ini”. The installed version can be observed from the “version=*.*.*” attribute within the file.
  • AVEVA's security bulletin LFSEC00000128 is available at the following location:

Affected Vendors

AVEVA Software, LLC

Affected Products (2)

AVEVA Software, LLC · InTouch Machine Edition 2017 8.1 | 2017 8.1 SP1
AVEVA Software, LLC · InduSoft Web Studio 8.1 | 8.1 SP1

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems, and Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more