SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2018-10628

CRITICAL · CVSS 9.8 EPSS 5.43% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-24 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. Public exploit code or proof-of-concept references have been detected in its references. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-10628
Severity
CRITICAL
CVSS
9.8
EPSS
5.43%

Original NVD Description

AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)