An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.
2023-12-16T01:15:07.367
2024-11-21T06:28:10.897
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | aveva | edge | < 2020 | Yes |
Application | aveva | edge | 2020 | Yes |
Application | aveva | edge | 2020 | Yes |
Application | aveva | edge | 2020 | Yes |