Known vulnerabilities in InTouch Access Anywhere
Vendor:
AVEVA Software, LLC.
Software:
InTouch Access Anywhere
Software CPE:
cpe:2.3:a:aveva_software:intouch_access_anywhere:*:*:*:*:*:*:*:*
Website:
https://www.aveva.com/
Total vulnerabilities:
3
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU70086 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-23854 |
CWE-22 | Medium | 2020b version 20.0.1 Hotfix, 2020 R2 version 20.1.0 Hotfix | 09.12.2022 |
SB2022120912 |
||
| #VU63040 - Exposure of resource to wrong sphere CVE-2022-1467 |
CWE-668 | Medium | - | 11.05.2022 |
SB2022051121 |
||
| #VU14150 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2015-9251 |
CWE-79 | Low | - | 31.07.2018 |
SB2018080106 SB2019011705 SB2019100301 and 63 more |