Known vulnerabilities in InTouch Edge HMI
Vendor:
AVEVA Software, LLC.
Software:
InTouch Edge HMI
Software CPE:
cpe:2.3:a:aveva_software:intouch_edge_hmi:*:*:*:*:*:*:*:*
Website:
https://www.aveva.com/
Total vulnerabilities:
8
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU17383 - Improper Control of Resource Identifiers ('Resource Injection') CVE-2019-6545 |
CWE-99 | High | 2017 Update 3 | 06.02.2019 |
SB2019020610 |
||
| #VU17382 - Missing Authentication for Critical Function CVE-2019-6543 |
CWE-306 | High | 2017 Update 3 | 05.02.2019 |
SB2019020610 |
||
| #VU15701 - Empty password in configuration file CVE-2018-17914 |
CWE-258 | High | 2017 SP2 | 02.11.2018 |
SB2018110209 |
||
| #VU15700 - Stack-based buffer overflow CVE-2018-17916 |
CWE-121 | High | 2017 SP2 | 01.11.2018 |
SB2018110209 |
||
| #VU13926 - Stack-based buffer overflow CVE-2018-10620 |
CWE-121 | High | 81.1.00.08 | 19.07.2018 |
SB2018072005 |
||
| #VU11894 - Stack-based buffer overflow CVE-2018-8840 |
CWE-121 | High | - | 17.04.2018 |
SB2018041808 |
||
| #VU9166 - Stack-based buffer overflow CVE-2017-14024 |
CWE-121 | High | - | 09.11.2017 |
SB2017111002 |
||
| #VU8572 - Missing Authentication for Critical Function CVE-2017-13997 |
CWE-306 | High | - | 22.09.2017 |
SB2017092202 |