CVE-2021-42797: Path Traversal
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42797?
CVE-2021-42797 is considered a critical vulnerability due to its potential to allow unauthorized access to sensitive data by stealing Windows access tokens.
How do I fix CVE-2021-42797?
To fix CVE-2021-42797, upgrade your AVEVA Edge software to a version released after R2020, which address this vulnerability.
What versions of AVEVA Edge are affected by CVE-2021-42797?
CVE-2021-42797 affects AVEVA Edge versions R2020 and all previous versions, including InduSoft Web Studio.
What are the potential consequences of CVE-2021-42797?
The exploitation of CVE-2021-42797 could lead to unauthorized access to external database resources and exposure of sensitive user credentials.
Who is at risk from CVE-2021-42797?
Organizations using affected versions of AVEVA Edge are at risk, particularly those that connect to external databases without proper access controls.