← Back

Aveva

aveva

68 CVEs • 35 products

Products (35)

Click to collapse
Toggle
Aveva Edge
aveva_edge
Clearscada
clearscada
Edge
edge
Suitelink
suitelink
Work Tasks
work_tasks
Intouch 2017
intouch_2017
Historian
historian
Intouch
intouch
Plant Scada
plant_scada
Pi Server
pi_server
Intouch 2014
intouch_2014
Intouch 2020
intouch_2020
Iec870ip
iec870ip

CVEs (68)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aveva
1Aveva Edge
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the t...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of APP files. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17114.Show less
1Aveva
1Aveva Edge
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the t...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of APP files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17212.Show less
1Aveva
2Aveva Plant Scada
Telemetry Server
Jun 17, 2026
Mar 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper...Show more
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.Show less
1Aveva
1Intouch Access Anywhere
Jun 17, 2026
Dec 23, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway w...Show more
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.Show less
1Aveva
7Batch Management
Enterprise Data ManagementManufacturing Execution System+4 more
Jun 17, 2026
Jul 27, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more...Show more
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.Show less
1Aveva
2Intouch Access Anywhere
Plant Scada Access Anywhere
Jun 17, 2026
May 23, 2022
N/A· v4
9.9 CRITICAL· v3
8.5 HIGH· v2
Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywher...Show more
Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.Show less
1Aveva
1System Platform
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.
1Aveva
1System Platform
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.
1Aveva
1System Platform
Jun 17, 2026
Apr 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.
1Aveva
1System Platform
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.
1Aveva
1System Platform
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the softw...Show more
AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.Show less
1Aveva
1System Platform
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.
1Aveva
1Suitelink
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper handling of exceptional conditions in SuiteLink server while processing command 0x01
1Aveva
1Suitelink
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Null pointer dereference in SuiteLink server while processing command 0x0b
1Aveva
1Suitelink
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a
1Aveva
1Suitelink
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Null pointer dereference in SuiteLink server while processing command 0x07
1Aveva
1Suitelink
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Null pointer dereference in SuiteLink server while processing commands 0x03/0x10
1Aveva
1Suitelink
Jun 17, 2026
Sep 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06
1Aveva
2Intouch 2017
Intouch 2020
Jun 17, 2026
Jun 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it...Show more
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.Show less
1Aveva
1Edna Enterprise Data Historian
Jun 17, 2026
Sep 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthentica...Show more
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.Show less