Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-16T00:00:00

Updated: 2024-08-04T03:38:50.223Z

Reserved: 2021-10-21T00:00:00

Link: CVE-2021-42797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-16T01:15:07.587

Modified: 2024-11-21T06:28:11.290

Link: CVE-2021-42797

cve-icon Redhat

No data.