CVE-2018-8840: InduSoft Web Studio

Critical severity, CVSS 9.8. EPSS: 8.6% chance of exploitation in the next 30 days.

A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.

Affected products

Published 2018-04-18. Last modified 2026-06-17.