AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.
2018-07-24T18:29:00.233
2024-11-21T03:41:41.730
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | aveva | intouch_2014 | r2 | Yes |
| Application | aveva | intouch_2014 | r2 | Yes |
| Application | aveva | intouch_2017 | - | Yes |
| Application | aveva | intouch_2017 | - | Yes |
| Application | aveva | intouch_2017 | - | Yes |