Known vulnerabilities in AVEVA Edge 2020 R2
Vendor:
AVEVA Software, LLC.
Software:
AVEVA Edge
Version:
2020 R2
Software CPE:
cpe:2.3:a:aveva_software:indusoft_web_studio:*:*:*:*:*:*:*:*
Website:
https://www.aveva.com/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU69521 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-42797 |
CWE-22 | High | 2020 R2 SP2 | 23.11.2022 |
SB2022112309 |
||
| #VU69520 - Improper Access Control CVE-2021-42796 |
CWE-284 | High | 2020 R2 SP2 | 23.11.2022 |
SB2022112309 |
||
| #VU69519 - Exposure of sensitive information to an unauthorized actor CVE-2021-42794 |
CWE-200 | Medium | 2020 R2 SP2 | 23.11.2022 |
SB2022112309 |
||
| #VU40450 - Improper input validation CVE-2016-2542 |
CWE-20 | Low | 2020 R2 SP2 | 24.02.2016 |
SB2016022406 SB2022112309 SB2016062711 |