CVE-2019-6525

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aveva:wonderware_system_platform:2017:update_2:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:2017:-:*:*:*:*:*:*
cpe:2.3:a:aveva:wonderware_system_platform:2017:update_1:*:*:*:*:*:*

Information

Published : 2019-04-11 14:29

Updated : 2020-10-16 10:39


NVD link : CVE-2019-6525

Mitre link : CVE-2019-6525


JSON object : View

CWE
CWE-269

Improper Privilege Management

Advertisement

dedicated server usa

Products Affected

aveva

  • wonderware_system_platform