Vulnerabilities (CVE)

Filtered by vendor Aveva Subscribe
Filtered by product Wonderware Intouch Access Anywhere
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-5156 1 Aveva 1 Wonderware Intouch Access Anywhere 2021-09-09 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.