CVE-2021-42794 โ€” Edge vulnerability

3 documents3 sources
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 44.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16

Description

An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

โ–ถNVDaveva/edge< 2020+1

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-r275-q95r-mr46: An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and priorโ†—2023-12-16
โ–ถ
CVEList
CVE-2021-42794: An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and priorโ†—2023-12-16
โ–ถ
CVE-2021-42794 โ€” Aveva Edge vulnerability | cvebase