Aveva
aveva
68 CVEs • 35 products
Products (35)
Click to collapseToggle
Products (35)
Click to collapse
CVEs (68)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Aveva 1Edna Enterprise Data Historian Jun 17, 2026 Sep 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unaut...Show more |
1Aveva 1Edna Enterprise Data Historian Jun 17, 2026 Sep 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data co...Show more |
1Aveva 1Edna Enterprise Data Historian Jun 17, 2026 Sep 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compr...Show more |
1Aveva 1Edna Enterprise Data Historian Jun 17, 2026 Sep 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data co...Show more |
The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash. |
1Aveva 1Wonderware System Platform Jun 17, 2026 Apr 11, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to...Show more |
1Aveva 2Indusoft Web Studio Intouch Machine Edition 2014Jun 17, 2026 Feb 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database...Show more |
1Aveva 2Indusoft Web Studio Intouch Machine Edition 2014Jun 17, 2026 Feb 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could le...Show more |
1Aveva 3Edge Indusoft Web StudioIntouch Machine Edition 2014Nov 21, 2024 Nov 2, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer o...Show more |
1Aveva 3Edge Indusoft Web StudioIntouch Machine Edition 2014Nov 21, 2024 Nov 2, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the...Show more |
1Aveva 2Intouch 2014 Intouch 2017Nov 21, 2024 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a...Show more |
1Aveva 2Indusoft Web Studio Intouch Machine 2017Nov 21, 2024 Jul 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, a...Show more |
2Aveva Schneider Electric2Clearscada ClearscadaNov 21, 2024 May 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the Cl...Show more |
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected be...Show more |
1Aveva 1Wonderware Intouch Access Anywhere May 13, 2026 Apr 20, 2017 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer...Show more |
1Aveva 1Wonderware Intouch Access Anywhere May 13, 2026 Apr 20, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary de...Show more |
1Aveva 1Wonderware Intouch Access Anywhere May 13, 2026 Apr 20, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external si...Show more |
2Aveva Schneider Electric2Aveva Edge Wonderware Intouch 2014May 6, 2026 Mar 29, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obta...Show more |
2Aveva Schneider Electric2Aveva Edge Wonderware Intouch 2014May 6, 2026 Mar 29, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information...Show more |
2Aveva Schneider Electric2Aveva Edge Wonderware Intouch 2014May 6, 2026 Mar 29, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote...Show more |