AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-342-02 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-12-23 13:15
Updated : 2023-01-04 10:15
NVD link : CVE-2022-23854
Mitre link : CVE-2022-23854
JSON object : View
CWE
CWE-23
Relative Path Traversal
Products Affected
aveva
- intouch_access_anywhere