First published: Sat Dec 16 2023(Updated: )
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA Edge | ||
AVEVA Edge 2020 R2 SP1 | ||
AVEVA InduSoft Web Studio | ||
AVEVA Edge 2020 R2 SP1 | <2020 | |
AVEVA Edge 2020 R2 SP1 | =2020 | |
AVEVA Edge 2020 R2 SP1 | =2020-r2 | |
AVEVA Edge 2020 R2 SP1 | =2020-r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42796 has a severity rating of critical due to the potential for unauthorized command execution.
To fix CVE-2021-42796, upgrade to a later version of AVEVA Edge that addresses this vulnerability.
CVE-2021-42796 affects AVEVA Edge versions R2020 and prior.
Yes, CVE-2021-42796 can be exploited remotely as it allows unauthenticated command execution.
CVE-2021-42796 allows for arbitrary command execution, which can lead to system compromise.