Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
References
Link Resource
https://www.aveva.com/en/products/edge/ Product
https://www.cisa.gov/news-events/ics-advisories/icsa-22-326-01 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-16T00:00:00

Updated: 2023-12-16T01:10:08.013113

Reserved: 2021-10-21T00:00:00


Link: CVE-2021-42797

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-16T01:15:07.587

Modified: 2023-12-20T17:32:50.487


Link: CVE-2021-42797

JSON object: View

cve-icon Redhat Information

No data.

CWE