7.5
CVSSv3

CVE-2021-42797

Published: 16/12/2023 Updated: 20/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aveva edge 2020

aveva edge

ICS Advisories

AVEVA Edge
Critical Infrastructure Sectors: Critical Manufacturing