CVE-2021-42797

high

Description

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

References

https://www.cisa.gov/news-events/ics-advisories/icsa-22-326-01

https://www.aveva.com/en/products/edge/

Details

Source: Mitre, NVD

Published: 2023-12-16

Updated: 2023-12-20

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00296