AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-2700 AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-16T19:09:25.647Z

Reserved: 2018-05-01T00:00:00

Link: CVE-2018-10628

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-24T18:29:00.233

Modified: 2024-11-21T03:41:41.730

Link: CVE-2018-10628

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.