CVE-2022-23854

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aveva:intouch_access_anywhere:*:*:*:*:*:*:*:*
cpe:2.3:a:aveva:intouch_access_anywhere:2020:-:*:*:*:*:*:*
cpe:2.3:a:aveva:intouch_access_anywhere:2020:r2:*:*:*:*:*:*

History

19 Jan 2024, 19:15

Type Values Removed Values Added
References
  • () https://crisec.de/advisory-aveva-intouch-access-anywhere-secure-gateway-path-traversal -
Summary
  • (es) AVEVA InTouch Access Anywhere versiones 2020 R2 y anteriores son vulnerables a una explotación de path traversal que podría permitir a un usuario no autenticado con acceso a la red leer archivos en el sistema fuera del servidor web de puerta de enlace segura.

17 Jan 2024, 07:15

Type Values Removed Values Added
References
  • () https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2023-001_r.pdf -

07 Nov 2023, 03:44

Type Values Removed Values Added
Summary AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server. AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

23 Jun 2023, 18:42

Type Values Removed Values Added
CWE CWE-23 CWE-22

04 Jan 2023, 18:15

Type Values Removed Values Added
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-342-02 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-342-02 - Third Party Advisory, US Government Resource
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:aveva:intouch_access_anywhere:*:*:*:*:*:*:*:*
cpe:2.3:a:aveva:intouch_access_anywhere:2020:-:*:*:*:*:*:*
cpe:2.3:a:aveva:intouch_access_anywhere:2020:r2:*:*:*:*:*:*
First Time Aveva intouch Access Anywhere
Aveva

23 Dec 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-23 21:15

Updated : 2024-01-19 19:15


NVD link : CVE-2022-23854

Mitre link : CVE-2022-23854

CVE.ORG link : CVE-2022-23854


JSON object : View

Products Affected

aveva

  • intouch_access_anywhere
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-23

Relative Path Traversal