Back to Database
Status published
High
CVE-2019-6525
AVEVA Wonderware System Platform 2017 Update 2 and prior uses...
Vulnerability Description
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-6525
Credits & Attribution
No credits recorded in the NVD database.
References
More from AVEVA
View All →CVE-2025-9317
AVEVA Edge Use of a Broken or Risky Cryptographic Algorithm
High
8.3
CVE-2025-8386
AVEVA Application Server IDE Basic Cross-site Scripting
High
7.2
CVE-2025-65118
AVEVA Process Optimization Uncontrolled Search Path Element
Critical
9.3
CVE-2025-65117
AVEVA Process Optimization Use of Potentially Dangerous Function
High
8.5
CVE-2025-64769
AVEVA Process Optimization Cleartext Transmission of Sensitive Information
High
7.6
Affected Vendor
AVEVA
View all reports →Affected Software
Wonderware System Platform
Vulnerable Versions:
2017 Update 2 and prior
Timeline
Official Publish:
April 11th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H