First published: Sat Dec 16 2023(Updated: )
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA Edge | <2020 | |
AVEVA Edge | =2020 | |
AVEVA Edge | =2020-r2 | |
AVEVA Edge | =2020-r2 | |
AVEVA Edge 2020 R2 SP1 | ||
AVEVA Edge 2020 R2 SP1 w/ HF 2020.2.00.40 | ||
AVEVA Edge 2020 R2 and all prior versions (formerly known as InduSoft Web Studio) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.