Stack-based buffer overflow in AVEVA Edge and InTouch Edge HMI - CVE-2018-10620
Published: July 19, 2018 / Updated: July 20, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to stack-based buffer overflow during tag, alarm, or event related actions such as read and write. A remote unauthenticated attacker can send a specially crafted packet, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
InTouch Edge HMI
How to mitigate CVE-2018-10620
InTouch Edge HMI - update to 81.1.00.08