VDB
CVE-2021-42797
CVE-2021-42797
PUBLISHED
CVSS 7.5 HIGH
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
EPSS 1.00% · 61.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.00%
61.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| aveva | edge | 0, 2020, 2020 |
Timeline
- Dec 16, 2023 CVE Published
- Dec 16, 2023 EPSS Score
- Jan 15, 2024 EPSS Score
- Feb 14, 2024 EPSS Score
- Mar 14, 2024 EPSS Score
- Apr 13, 2024 EPSS Score
- Jun 12, 2024 EPSS Score
- Jul 12, 2024 EPSS Score
- Aug 4, 2024 CVE Updated
- Aug 10, 2024 EPSS Score
- Sep 9, 2024 EPSS Score
- Oct 9, 2024 EPSS Score