CVE-2021-42794: Infoleak
An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42794?
CVE-2021-42794 has been identified as a significant vulnerability that allows potential port scanning of the LAN.
How do I fix CVE-2021-42794?
To mitigate CVE-2021-42794, users should upgrade to a patched version of AVEVA Edge beyond version R2020.
What kind of attack does CVE-2021-42794 facilitate?
CVE-2021-42794 facilitates connection string parameter pollution attacks that could allow an adversary to conduct port scans.
Which versions of AVEVA Edge are affected by CVE-2021-42794?
CVE-2021-42794 affects AVEVA Edge versions R2020 and all prior versions.
Is there a workaround for CVE-2021-42794?
Currently, the most effective mitigation for CVE-2021-42794 is to upgrade the software to a version that addresses the vulnerability.