ICSA-20-254-01: Aveva enterprise data management vulnerability
Affected Software
1 affected component
AVEVA Enterprise Data Management Web v2019 and prior
Event History
Feb 21, 2025
Advisory Published
01:59 PM
Frequently Asked Questions
1
What is the severity of ICSA-20-254-01?
The severity of ICSA-20-254-01 is rated as critical due to the potential for unauthorized access and manipulation of sensitive data.
2
How do I fix ICSA-20-254-01?
To fix ICSA-20-254-01, users should upgrade to AVEVA Enterprise Data Management Web version 2020 or later to mitigate the identified vulnerabilities.
3
What vulnerabilities are associated with ICSA-20-254-01?
ICSA-20-254-01 is associated with multiple vulnerabilities that allow for cross-site request forgery and authentication bypass.
4
What systems are affected by ICSA-20-254-01?
ICSA-20-254-01 affects AVEVA Enterprise Data Management Web v2019 and earlier versions.
5
Are there any workarounds for ICSA-20-254-01?
No official workarounds are provided for ICSA-20-254-01; the recommended action is to update to the latest version.