Loading
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
Use CWE-121, Indusoft vendor hub and Web Studio product page to widen CVE-2018-8840 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-0780, CVE-2011-4051 and CVE-2011-0342 for nearby disclosures in the same product family.