Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-42797


Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.


Published

2023-12-16T01:15:07.587

Last Modified

2024-11-21T06:28:11.290

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application aveva edge < 2020 Yes
Application aveva edge 2020 Yes
Application aveva edge 2020 Yes
Application aveva edge 2020 Yes

References