CVE-2022-23854: Path Traversal
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-23854?
CVE-2022-23854 is a vulnerability in AVEVA InTouch Access Anywhere versions 2020 R2 and older that allows an unauthenticated user to read files on the system outside of the secure gateway web server.
How severe is CVE-2022-23854?
CVE-2022-23854 has a severity rating of 7.5 (high).
Which versions of AVEVA InTouch Access Anywhere are affected by CVE-2022-23854?
CVE-2022-23854 affects AVEVA InTouch Access Anywhere versions 2020 R2 and older.
How can an unauthenticated user exploit CVE-2022-23854?
An unauthenticated user with network access can exploit CVE-2022-23854 to perform a path traversal attack and read files on the system outside of the secure gateway web server.
Is there a fix for CVE-2022-23854?
It is recommended to upgrade to a version of AVEVA InTouch Access Anywhere that is not vulnerable to CVE-2022-23854.