5.3
CVSSv3

CVE-2021-42794

Published: 16/12/2023 Updated: 20/12/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aveva edge 2020

aveva edge

ICS Advisories

AVEVA Edge
Critical Infrastructure Sectors: Critical Manufacturing