CVE-2018-10620: Aveva InduSoft Web Studio

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed.

Affected products

  • Aveva InduSoft Web Studio: version 8.1 only
  • Aveva Intouch Machine 2017: version 8.1 only

Published 2018-07-19. Last modified 2026-06-17.