← Back

CVE-2021-42797

nvd nist
Published: Dec 16, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

Affected (4)

Products: Aveva: Edge
1 product
Edge
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Aveva
Before 2020
Version 2020
Version 2020 r2
Version 2020 r2

References (4)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.