First published: Sat Dec 16 2023(Updated: )
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA Edge | ||
AVEVA Edge 2020 R2 SP1 | ||
AVEVA InduSoft Web Studio | ||
AVEVA Edge 2020 R2 SP1 | <2020 | |
AVEVA Edge 2020 R2 SP1 | =2020 | |
AVEVA Edge 2020 R2 SP1 | =2020-r2 | |
AVEVA Edge 2020 R2 SP1 | =2020-r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42797 is considered a critical vulnerability due to its potential to allow unauthorized access to sensitive data by stealing Windows access tokens.
To fix CVE-2021-42797, upgrade your AVEVA Edge software to a version released after R2020, which address this vulnerability.
CVE-2021-42797 affects AVEVA Edge versions R2020 and all previous versions, including InduSoft Web Studio.
The exploitation of CVE-2021-42797 could lead to unauthorized access to external database resources and exposure of sensitive user credentials.
Organizations using affected versions of AVEVA Edge are at risk, particularly those that connect to external databases without proper access controls.