CVE-2022-23854

HIGH WAF: High
CVSS 7.5 Published: 2022-12-23
CWE-22

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

WAF Coverage Analysis

Path Traversal High WAF Coverage

OWASP: A01:2021 Broken Access Control

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
avevaintouch_access_anywhereup to 2020
avevaintouch_access_anywhere2020
avevaintouch_access_anywhere2020

References

Back to CVE Database